CVE-2024-6060

CRITICAL

Phloc Webscopes 7.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

Scores

CVSS v4 9.3
EPSS 0.0007
EPSS Percentile 21.7%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/AU:N/R:U/V:C/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (2)
Phloc/Webscopes 7.0.0
Phloc/Webscopes pkg:maven/com.phloc/[email protected]
Published Jun 25, 2024
Tracked Since Feb 18, 2026