The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. These emails are sent without using an encrypted transmission protocol. If an attacker intercepts the packets, they can obtain the plaintext session information and use it to log into the system.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-14 09:15
Updated : 2024-06-17 12:42
NVD link : CVE-2024-5996
Mitre link : CVE-2024-5996
CVE.ORG link : CVE-2024-5996
JSON object : View
Products Affected
No product.
CWE
CWE-319
Cleartext Transmission of Sensitive Information