Impact
RansomLook exposed sensitive operator‑side scraping configuration in multiple unauthenticated API responses. The API returned location records, including internal fields such as authentication headers, session cookies, init_script and browser information, to callers that were not logged in. This information disclosure allows an attacker to capture credentials that may be reused against monitored services and to learn and defeat RansomLook’s anti‑bot and captcha bypass mechanisms. The vulnerability is classified as a data confidentiality breach (CWE-200).
Affected Systems
The vulnerability affects the RansomLook platform. No specific product version was cited in the advisory, so all installations of the software that expose the described API endpoints are potentially impacted.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity data disclosure risk. The EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the weakness over the network by making unauthenticated requests to the affected API endpoints, requiring no prior access. Given the sensitive data exposed, the risk to confidentiality and the potential for later exploitation is high.
OpenCVE Enrichment