CVE-2019-13410

HIGH

TOPMeeting < 8.8 - Unauthenticated Exposure of Sensitive Information via Frontend Page Source

Title source: llm
STIX 2.1

Description

TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://www.twcert.org.tw/en/cp-128-3020-27eb5-2.html
Third Party Advisory x_refsource_confirm
https://tvn.twcert.org.tw/taiwanvn/TVN-201907002

Scores

CVSS v3 7.5
EPSS 0.0154
EPSS Percentile 71.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
topmeeting/topmeeting < 8.8
Published Oct 17, 2019
Tracked Since Feb 18, 2026