PT-2023-11731 · Unknown · Cms-Dev/Cms

Niuzhi

·

Published

2023-08-11

·

Updated

2023-08-17

·

CVE-2020-24804

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions cms-dev/cms version 1.4.rc1
Description The issue allows attackers to gain sensitive information via audit logs due to a plaintext password vulnerability in AddAdmin.py.
Recommendations For version 1.4.rc1, consider disabling the AddAdmin.py script until a patch is available to prevent attackers from gaining sensitive information. Restrict access to audit logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24804

Affected Products

Cms-Dev/Cms