Brynamics · Brynamics Online Trade · CVE-2018-14328
**Name of the Vulnerable Software and Affected Versions**
Brynamics Online Trade (affected versions not specified)
**Description**
The issue allows remote attackers to obtain sensitive information via a direct request for specific API endpoints, including "/dashboard/addplan", "/dashboard/paywithcard/charge", "/dashboard/withdrawal", or "/privacy&terms". This can lead to the exposure of database credentials, such as `database username`, `database password`, `database name`, and IP address fields.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.