PT-2021-24079 · Unknown · Bus Pass Management System
Published
2021-12-16
·
Updated
2023-11-14
·
CVE-2021-44315
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Bus Pass Management System version 1.0
Description:
The issue allows an attacker to view sensitive files of the application due to Directory Listing/Browsing being enabled on the web server. This can include files containing sensitive user or server information.
Recommendations:
For Bus Pass Management System version 1.0, disable Directory Listing/Browsing on the web server to prevent attackers from viewing sensitive files. Consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bus Pass Management System