CVE-2025-8528CWE-312CWE-315

Exrick xboot getMenuList sensitive information in a cookie

Medium · published August 4, 2025

CVSS v4.0
6.3
EPSS
0%
Percentile
21.9
In the wild
Unconfirmed
What it is

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

The record
Technical detail
CVSS v4.0
6.3 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00297 · 21.9th percentile
Weaknesses
CWE-312 · Cleartext Storage of Sensitive Information; CWE-315 · Cleartext Storage of Sensitive Information in a Cookie
Published
2025-08-04T22:02Z
EPSS history
Timeline
  • 04 AUG 22:02Z
    Exrick xboot getMenuList sensitive information in a cookie
    cvelistv5