CVE-2023-27587
HIGH EXPLOITED NUCLEIReadtomyshoe < 2023-03-13 - Error Information Exposure
Title source: ruleDescription
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates from the Google Cloud TTS request, then it will include the full URL of the request. The request URL contains the Google Cloud API key. This has been patched in commit 8533b01. Upgrading should be accompanied by deleting the current GCP API key and issuing a new one. There are no known workarounds.
Exploits (2)
Nuclei Templates (1)
ReadToMyShoe - Generation of Error Message Containing Sensitive Information
MEDIUMby vagnerd
Scores
CVSS v3
7.4
EPSS
0.8749
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Details
VulnCheck KEV
2024-01-22
CWE
CWE-209
Status
published
Products (1)
readtomyshoe_project/readtomyshoe
< 2023-03-13
Published
Mar 13, 2023
Tracked Since
Feb 18, 2026