Exrick xboot getMenuList sensitive information in a cookie

CVE Details

Basic Information

Title Exrick xboot getMenuList sensitive information in a cookie
Type cve
Published 2025-08-04T22:02:06.163Z
Modified 2025-08-04T22:02:06.163Z

Product Information

Vendor Exrick
Product xboot
Version 3.3.0

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description Exrick xboot versions up to 3.3.4 store sensitive information in cookies insecurely, potentially exposing user data. This is a Medium severity issue.
AI Severity Medium
AI Vendor Exrick
AI Product xboot
AI Version 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4

Affected Products

  • Exrick xboot 3.3.0
  • Exrick xboot 3.3.1
  • Exrick xboot 3.3.2
  • Exrick xboot 3.3.3
  • Exrick xboot 3.3.4

Additional Information

CWE List CWE-315, CWE-312
Source VulDB

Description

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.