Mersive Solstice Pod
cpe:2.3:h:mersive:solstice_pod:*:*:*:*:*:*:*, +1 more
- 5.5
- 6.2
This vulnerability is being actively exploited in the wild.
An unauthenticated API endpoint in Mersive Solstice Pod versions 5.5 and 6.2 exposes sensitive information, including the session key, server version, product details, and display name. Unauthorized users can access this endpoint to extract live session information without authentication.
Exploitation of this vulnerability allows unauthorized users to access sensitive session information, which could lead to further exploitation or unauthorized access.
The vulnerability can be reproduced by sending a GET request to the '/api/config' endpoint on a Solstice Pod server. This request can be made without any authentication, and it will return a JSON response containing the session key, server version, product name, product variant, and display name.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.