CVE-2014-1930
Summary
| CVE | CVE-2014-1930 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-10 22:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS: 0.008250000 probability, percentile 0.745290000 (date 2026-05-04)
Problem Types: CWE-200 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Visibility Software | Cyber Recruiter | 6.2 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | 6.4 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | 6.6 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | 6.8 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | 7.0 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | 7.2 | All | All | All |
| Application | Visibility Software | Cyber Recruiter | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/102815 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Vulnerability Note VU#566894 - Visibility Software Cyber Recruiter authentication bypass vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| JVNVU#97441356: Visibility Software Cyber Recruiter に認証回避の脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Visibility Software Cyber Recruiter Multiple Authentication Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/102814 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cyber Recruiter - Powered by HelpConsole 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.vspublic.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.