PT-2019-12206 · Excellent Infotek · Biyan

Keniver Wang

+1

·

Publicado

2019-06-19

·

Atualizado

2020-08-24

·

CVE-2019-11232

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EXCELLENT INFOTEK BiYan versions 1.57 through 2.8
Description The issue allows an attacker to leak user information, specifically passwords, without authentication. This is achieved by sending an EMP NO element to the "kws login/asp/query user.asp" API endpoint and then reading the PWD element.
Recommendations For versions 1.57 through 2.8, consider restricting access to the "kws login/asp/query user.asp" API endpoint to prevent unauthorized password leaks. As a temporary workaround, avoid using the EMP NO element in this endpoint until a fix is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11232

Produtos afetados

Biyan