Skip to main content

Threats Tagged 'cwe-1230'

View all threats tagged with 'cwe-1230'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1230

Threats Tagged 'cwe-1230'

Click on any threat for detailed analysis and mitigation recommendations

Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.

Join the discussion

Nextcloud versions from 0.8.0 up to but not including 1.0.4 have a vulnerability where view filter criteria in Nextcloud Tables are exposed to users with read-only permissions. This exposure of metadata could reveal sensitive information unintentionally. The issue has been addressed and patched in versions 1.0.4 and later.

Join the discussion

Apache ActiveMQ Broker versions before 5.19.7 and from 6.0.0 before 6.2.6 have a vulnerability that allows unauthenticated attackers to obtain sensitive metadata about durable topic subscriptions. This includes client identifiers, subscription names, topic destinations, and JMS selector expressions. The issue arises when brokers are configured with a network connector with syncDurableSubs set to true and respond to BrokerInfo commands without verifying authentication. Upgrading to versions 5.19.7 or 6.2.6 resolves this vulnerability.

Join the discussion

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Join the discussion

Tandoor Recipes versions prior to 2.6.0 do not strip EXIF metadata from uploaded WebP and GIF images. This leads to exposure of sensitive information such as GPS coordinates, camera model, timestamps, and software details to any user who can view the recipe images. The issue is fixed in version 2.6.0.

Join the discussion

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.

Join the discussion
0

CVE-2025-13084 is a high-severity vulnerability in Opto 22's groov View Server R1.0a where the users endpoint in the API exposes all users' metadata including API keys to any user with Editor role privileges. This exposure includes Administrator API keys, potentially allowing privilege escalation or unauthorized access to critical system functions. The vulnerability requires network access and Editor-level privileges but no user interaction, and it impacts confidentiality and availability. No known exploits are currently reported in the wild. European organizations using groov View Server in industrial control or automation environments are at risk, especially those with Editor role users who might be targeted or compromised. Mitigation requires restricting Editor role assignments, monitoring API access logs, and applying vendor patches once available. Countries with significant industrial automation sectors and Opto 22 deployments, such as Germany, France, Italy, and the UK, are most likely to be affected. The CVSS score of 7.6 reflects the high confidentiality impact and ease of exploitation with low attack complexity.

Join the discussion

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.

Join the discussion

Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

Join the discussion

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specified text in the title. The visibility state (`mybb_threads.visible` integer column) of threads is not validated in internal search queries, whose result is used to output a general success or failure of the search. While MyBB validates permissions when displaying the final search results, a search operation that internally produces at least one result outputs a redirect response (as a HTTP redirect, or a success message page with delayed redirect, depending on configuration). On the other hand, a search operation that internally produces no results outputs a corresponding message in the response without a redirect. This allows a user to determine whether threads matching title search parameters exist, including draft threads (`visible` with a value of `-2`), soft-deleted threads (`visible` with a value of `-1`), and unapproved threads (`visible` with a value of `0`); in addition to displaying generally visible threads (`visible` with a value of `1`). This vulnerability does not affect other layers of permissions. In order to exploit the vulnerability, the user must have access to the search functionality, and general access to forums containing the thread(s). The vulnerability does not expose the message content of posts. MyBB 1.8.39 resolves this issue.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: cwe-1230
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses