Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xh2-cv46-rpfc

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.

CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.

EPSS

Процентиль: 52%
0.00294
Низкий

Связанные уязвимости

nvd
больше 21 года назад

CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.

EPSS

Процентиль: 52%
0.00294
Низкий