{"id":"CVE-2026-14838","published":"2026-08-04T10:19:32.540","lastModified":"2026-08-04T13:17:36.027","description":"Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":7.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-598"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a session hijacking vulnerability due to sensitive query strings being exposed via GET requests. This matters because attackers can exploit it to take over user sessions.","exploitability":"Exploitation requires access to sensitive query parameters, making it moderately difficult but feasible with proper reconnaissance.","blast_radius":"If exploited, the impact could be significant as it allows full session hijacking, potentially leading to unauthorized access and data breaches.","remediation":"Update to HUMANIST Digital Human Resources version 26.1 or later which addresses this vulnerability.","tags":["session-hijacking","web","vulnerability","update"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:59:53.027Z"}}