CVE Database
/

CVE-2022-25151

Back to search

CVE-2022-25151

Published: Jun 8, 2022

Modified: Mar 11, 2025

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.

VendorProductVersions

ITarian

ITarian SaaS platform / on-premise

affected
any version - < 6.35.37347.20040

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

https://csirt.divd.nl/DIVD-2021-00037
x_refsource_CONFIRM
related
https://csirt.divd.nl/CVE-2022-25151
x_refsource_CONFIRM
third-party-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now