Проблема в Bottinelli Informatica Vedo Suite v.1.2.5 позволяет удаленному злоумышленнику получить конфиденциальную информацию через конечную точку api_vedo/chat и параметр utente_chat.
Показать оригинальное описание (EN)
An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter