DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
2022-01-21T21:15:09.107
2024-11-21T06:47:00.603
Modified
CVSSv3.1: 8.3 (HIGH)
AV:A/AC:L/Au:N/C:P/I:P/A:P
6.5
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | emc_appsync | < 4.4.0.0 | Yes |