CVE-2025-24948

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:joturl:joturl:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-15 16:16

Updated : 2025-04-22 18:41


NVD link : CVE-2025-24948

Mitre link : CVE-2025-24948

CVE.ORG link : CVE-2025-24948


JSON object : View

Products Affected

joturl

  • joturl
CWE
CWE-598

Use of GET Request Method With Sensitive Query Strings