Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2r4-xgw7-33cp

Опубликовано: 02 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.

EPSS

Процентиль: 41%
0.00189
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.

EPSS

Процентиль: 41%
0.00189
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-522