CVE Vulnerabilities

CVE-2025-59873

Use of GET Request Method With Sensitive Query Strings

Published: Feb 23, 2026 | Modified: Feb 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information exposure vulnerability exists in

Vulnerability in HCL Software ZIE for Web.

The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site linked from the application can hijack user sessions

This issue affects ZIE for Web: v16.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Potential Mitigations

References