vendor:
Adlisting Classified Ads
by:
CraCkEr
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Adlisting Classified Ads
Affected Version From: 2.14.0
Affected Version To: 2.14.0
Patch Exists: YES
Related CWE: CVE-2023-4168
CPE: a:templatecookie:adlisting_classified_ads:2.14.0
Platforms Tested: Windows 10 Pro
2023
Adlisting Classified Ads 2.14.0 – WebPage Content Information Disclosure
Information disclosure issue in the redirect responses, exposing sensitive data such as API keys, server keys, and app IDs in the body of the redirects.
Mitigation:
Implement proper access controls and ensure sensitive data is not exposed in redirect responses. Update the Firebase Push Notification Configuration to remove sensitive information.