PT-2024-24241 · Italtel · Italtel Embrace
Fabio Romano
+3
·
Published
2024-05-21
·
Updated
2024-07-26
·
CVE-2024-31844
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Italtel Embrace version 1.6.4
Description
An issue was discovered where the server does not properly handle application errors, leading to a disclosure of information about the server. An unauthenticated user can craft specific requests to make the application generate an error, revealing information such as the absolute path of the source code of the application. This information can help an attacker perform other attacks against the system. The issue can be exploited without authentication.
Recommendations
For Italtel Embrace version 1.6.4, consider implementing proper error handling mechanisms to prevent information disclosure. As a temporary workaround, restrict access to error messages to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Italtel Embrace