peter bassill · operator
$ cve CVE-2014-0999 JSON

CVE-2014-0999 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.6% (pctl 94)

Patch early

A public exploit exists.

Description

Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS6.6% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2015-06-02
Last modified2026-06-17

Affected (1)

VendorProduct
sendiosendio

Public exploits

SourceTitleDate
exploit-dbSendio ESP - Information Disclosure2015-05-26

References

→ the Explorer  ·  watch your stack  ·  NVD