Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.
References
Link Resource
https://csirt.divd.nl/CVE-2022-25151 Third Party Advisory
https://csirt.divd.nl/DIVD-2021-00037 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: DIVD

Published: 2022-02-23T00:00:00

Updated: 2024-05-22T20:18:15.627Z

Reserved: 2022-02-14T00:00:00


Link: CVE-2022-25151

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-09T17:15:08.787

Modified: 2023-06-23T18:57:58.710


Link: CVE-2022-25151

JSON object: View

cve-icon Redhat Information

No data.