In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
History

Mon, 06 Oct 2025 07:15:00 +0000

Type Values Removed Values Added
Description In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
Title Plain Text Transmission of Username and Password in the URL
Weaknesses CWE-598
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2025-10-06T07:01:04.945Z

Reserved: 2025-09-03T08:58:14.356Z

Link: CVE-2025-58584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-06T07:15:35.063

Modified: 2025-10-06T07:15:35.063

Link: CVE-2025-58584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.