← voltar
CVE-2024-4300

E-WEBInformationCo. FS-EZViewer(Web) - Sensitive Data Exposure

CVSS 9.8 CRITICALEPSS 0.8%CWE-200
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
29 abr 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →