Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Gainsight Assist plugin information disclosure
Vulnerability Description
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过GET请求中的查询字符串导致的信息暴露
Vulnerability Title
Gainsight Assist 安全漏洞
Vulnerability Description
Gainsight Assist是Gainsight公司的一款客户沟通模板管理工具。 Gainsight Assist存在安全漏洞,该漏洞源于OAuth回调URL的state参数中暴露了base64编码的用户电子邮件地址,可能导致个人信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A