Skip to main content

CVE detail

CVE-2025-49188

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

CVSS 5.3 · Medium