PT-2024-31212 · Unknown · Titan Sftp+1
Mounir Aarab
·
Published
2024-09-13
·
Updated
2024-09-13
·
CVE-2024-44685
CVSS v3.1
5.0
Medium
| Vector | AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Titan SFTP and Titan MFT Server versions 2.0.25.2426 and earlier
Description
The issue concerns the exposure of sensitive information, including passwords, in clear text within the JSON response when configuring SMTP settings via the Web UI. This sensitive information exposure occurs in Titan SFTP and Titan MFT Server.
Recommendations
For versions 2.0.25.2426 and earlier, consider restricting access to the Web UI until a fix is available, and avoid configuring SMTP settings via the Web UI to minimize the risk of sensitive information exposure.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Titan Ftp Server
Titan Sftp