← volver
CVE-2024-6880

CSRF in MegaBIP

CVSS 6.9 MEDIUMEPSS 0.5%CWE-538
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.   This issue affects MegaBIP software versions below 5.15
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Jan Syski · MegaBIP

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →