Podatność w Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 pozwala zdalnemu atakującemu uzyskać wrażliwe informacje poprzez komunikaty błędów logowania. Atak polega na wykorzystaniu informacji ujawnianych w odpowiedziach systemu podczas procesu autoryzacji.
▸ Pokaż oryginał (EN)
An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCraws Openatlas
APPCraws< 8.12.1
Powiązane podatności
SQL Injection w OpenAtlas v8.11.0 (Austrian Archaeological Institute)
Hardcoded hasło administratora w OpenAtlas v8.11.0
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8...
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows ...
Nieprawidłowa kontrola dostępu w Austrian Archaeological Institute Openatlas przed wersją v8.12.0 pozwala atak...