What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is user tokens and other potentially sensitive information. According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability? A successful attacker could gain the Domain SID prefix for the targeted site. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.
<a href="https://twitter.com/testanull">Jang (Nguyễn Tiến Giang) of StarLabs SG</a> working with <a href="https://www.zerodayinitiative.com/">Trend Micro Zero Day Initiative</a>