Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-9425

Опубликовано: 20 мар. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rconfig:rconfig:*:*:*:*:*:*:*:*
Версия до 3.9.4 (исключая)

EPSS

Процентиль: 98%
0.49449
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-670

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

EPSS

Процентиль: 98%
0.49449
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-670