Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Any version
unknown
Description
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
Problem types
CWE-598 Use of GET request method with sensitive query strings
Product status
Any version
Credits
Christopher O’Boyle, Cybersecurity Advisor at Rapid7
References
www.rapid7.com/...ht-assist-information-disclosure-xss-fixed
communities.gainsight.com/...-31381-and-cve-2026-31382-30587