VulnerAlert



APPLICATION
BROWSER
15-12-2025 14:44

CVE-2025-34412 Vulnerabilidad documentada

Sin puntuación
Tags
#site
#cross
#source
#open
#form
#embedder
#cross-site
#asp.net
#browser
#application
#/cross(.*)cross/iU
#cross cross
#affected
#security
#protect
#issue
#fix
#attack
#affect
Descripción
The Convercent Whistleblowing Platform operated by EQS Group contains a protection mechanism failure in its browser and session handling. By default, affected deployments omit HTTP security headers such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, implement incomplete clickjacking protections. The application also issues cookies with insecure or inconsistent attributes including duplicate ASP.NET_SessionId values, an affinity cookie missing the Secure attribute, mixed absent SameSite settings. These deficiencies weaken browser-side isolation integrity, increasing exposure to client-side attacks, fixation, cross-site leakage.
https://seclists.org/fulldisclosure/2025/Dec/4
https://www.convercent.com/
https://www.eqs.com/en-us/platform-convercent-clients/
https://www.vulncheck.com/advisories/convercent-whisteblowing-platform-protection-mechanism-failure-insecure-default-browser-and-session-controls
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-34412
Resultados similares
Coincidentes en almenos en 50% de los tags
15-12-2025 CVE-2025-67634
The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable...
Ver información
15-12-2025 CVE-2025-43520
A memory corruption issue was addressed with improved memory handling. This issue is fixed in w...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por