CVE Vulnerabilities

CVE-2025-49188

Use of GET Request Method With Sensitive Query Strings

Published: Jun 12, 2025 | Modified: Jan 29, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
Field_analyticsSick**

Potential Mitigations

References