Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f92c-vmwr-rmv8

Опубликовано: 09 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 1.8

Описание

User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.

User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.

EPSS

Процентиль: 15%
0.00048
Низкий

1.8 Low

CVSS4

Дефекты

CWE-532

Связанные уязвимости

nvd
около 1 года назад

User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.

EPSS

Процентиль: 15%
0.00048
Низкий

1.8 Low

CVSS4

Дефекты

CWE-532