What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StreamWeasels StreamWeasels Twitch Integration.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StreamWeasels StreamWeasels Twitch Integration.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.8.
Explanation of Vulnerability in Simple Terms
StreamWeasels Twitch Integration versions 1.7.8 and earlier expose sensitive information over the network without requiring authentication. An attacker can read data that should be restricted, such as API tokens or user credentials, by making direct requests to the application. Update to a version newer than 1.7.8 to resolve this issue.
What an attacker can do
Read sensitive data like API tokens or user information without logging in.
Potential impact on your site
Exposed API tokens or user data could be used to compromise Twitch integration or user accounts.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities