CVE-2014-9575: Vdgsecurity Vdg Sense
Medium severity, CVSS 6.4. EPSS: 2.4% chance of exploitation in the next 30 days.
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
Affected products
- Vdgsecurity Vdg Sense: up to and including 2.3.14
Published 2015-01-08. Last modified 2026-06-17.