CVE-2026-103098
🟡 Monitoruj
Przesyłanie klucza w URL przez niezabezpieczone HTTP umożliwia jego przechwycenie przez atakującego.
CVSS
7.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 01:16:43 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 19:16:39 UTC |
Referencje
- https://www.geovision.com.tw/cyber_security.php (0df08a0e-a200-4957-9bb0-084f562506f9)