CVE-2025-24948
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-24948 is a vulnerability affecting JotUrl 2.0, where passwords are transmitted via insecure HTTP GET requests. This issue exposes credentials to potential eavesdropping or insecure recordkeeping, posing a significant security risk for users. The vulnerability allows unauthorized access to accounts if an attacker intercepts the transmission. The use of HTTP GET requests for passwords is not secure and contradicts best practices for handling sensitive information, increasing the likelihood of data breaches. Users of JotUrl 2.0 are urged to update to the latest version or employ alternative methods to secure their passwords.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.