Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6wp-x7wc-m898

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

EPSS

Процентиль: 89%
0.04651
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

EPSS

Процентиль: 89%
0.04651
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522