CVE-2026-103098
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-Eye | V3.6.0 | affected |
| GeoVision Inc. | GV-Eye | V3.7.2 | unaffected |
Weaknesses
- CWE-319: CWE-319 Cleartext transmission of sensitive information
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.