Fiche vulnérabilité
CVE-2026-22644 : faille élevée sick incoming goods suite (CVSS 7.5)
Description
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 janv. 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- sick incoming goods suite