Impact
V2Board versions up to 1.7.4 allow a server authentication token to be passed in a GET parameter, and the token is embedded in URLs such as "/api/v1/server/UniProxy/user?token=SECRET". This practice causes the token to be logged by web servers, stored in browser history, transmitted in HTTP Referer headers, and recorded by proxy/CDN logs. An attacker who obtains any of these log sources can retrieve the token and then use it to impersonate a proxy server node, potentially intercepting all traffic destined for the legitimate proxy.
Affected Systems
The vulnerability affects the V2Board application, specifically versions up to and including 1.7.4. No other vendors or products are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score is 5.3, indicating medium severity. EPSS is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote: an attacker who can access web server logs, browser history, or Referer headers can leverage the exposed token to impersonate the server.
OpenCVE Enrichment