CWE-598
93 CVEs • Abstraction: Variant
Use of GET Request Method With Sensitive Query Strings
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
CVEs (93)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are...Show more |
1Tp Link 1Tl Sg108e Firmware Jun 17, 2026 Jan 27, 2025 6.3 MEDIUM· v4 3.7 LOW· v3 2.6 LOW· v2 A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. T...Show more |
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about...Show more |
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques. |
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks. |
1Johnsoncontrols 1Exacqvision Web Service Jun 17, 2026 Aug 1, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Under certain circumstances the exacqVision Web Service can expose authentication token details within communications. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Jun 30, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776. |
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least...Show more |
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily interc...Show more |
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the pag...Show more |
1Ibm 2Maximo Application Suite Maximo Asset ManagementJun 17, 2026 Mar 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via...Show more |
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often...Show more |
Sametime is impacted by sensitive information passed in URL.
|
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
|
1Tribe29 1Checkmk Appliance Firmware Jun 17, 2026 Nov 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files. |
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. |
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if...Show more |
NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this tok...Show more |
1Tribe29 1Checkmk Appliance Firmware Jun 17, 2026 Apr 18, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. |
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored...Show more |