PT-2021-10709 · Unknown · Ave Dominaplus
Gjoko Krstic
·
Published
2021-04-28
·
Updated
2022-10-26
·
CVE-2020-21994
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
AVE DOMINAplus versions prior to 1.11
Description:
The issue allows an unauthenticated attacker to obtain administrative login information by accessing an unprotected directory that hosts an XML file '/xml/authClients.xml', enabling a successful authentication bypass attack.
Recommendations:
For versions prior to 1.11, restrict access to the '/xml/authClients.xml' file to prevent unauthorized disclosure of administrative login information. Consider protecting the directory that hosts this file to mitigate the risk of exploitation.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ave Dominaplus