Common Weakness Enumeration

    CWE Definition / CWE-598

    CWE-598: Use of HTTP Request With Sensitive Query String

    The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

    Published:15 Dec 2006
    Organization:MITRE
    Modified:30 Apr 2026

    Related Weakness

    CWE-201: Insertion of Sensitive Information Into Sent Data