Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23558 | A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 Aug 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Exrick
Exrick xboot |
|
| CPEs | cpe:2.3:a:exrick:xboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Exrick
Exrick xboot |
Tue, 05 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xboot Project
Xboot Project xboot |
|
| Vendors & Products |
Xboot Project
Xboot Project xboot |
Mon, 04 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. | |
| Title | Exrick xboot getMenuList sensitive information in a cookie | |
| Weaknesses | CWE-312 CWE-315 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-05T13:35:38.680Z
Reserved: 2025-08-04T06:51:27.628Z
Link: CVE-2025-8528
Updated: 2025-08-05T13:35:34.172Z
Status : Analyzed
Published: 2025-08-04T22:15:29.323
Modified: 2025-08-28T11:52:22.193
Link: CVE-2025-8528
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:38:50Z
EUVD