PT-2019-12423 · Doorgets · Doorgets

Publicado

2019-04-30

·

Atualizado

2020-08-24

·

CVE-2019-11616

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions doorGets version 7.0
Description The issue allows a remote unauthenticated attacker to disclose sensitive information. Specifically, the vulnerability is present in the /setup/temp/admin.php and /setup/temp/database.php API endpoints, which could be exploited to obtain the administrator password.
Recommendations For doorGets version 7.0, consider restricting access to the /setup/temp/admin.php and /setup/temp/database.php API endpoints to prevent exploitation until a fix is available. Additionally, changing the administrator password and monitoring for any suspicious activity is recommended.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-11616

Produtos afetados

Doorgets