CVE-2024-4300
E-WEBInformationCo. FS-EZViewer(Web) - Sensitive Data Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
E-WEBInformationCo. FS-EZViewer(Web) expone información confidencial en el servicio. Un atacante remoto puede obtener la ruta del archivo de configuración de la base de datos a través del código fuente de la página web sin iniciar sesión. Acceder a esta ruta permite al atacante obtener la credencial de la base de datos con el mayor privilegio y la dirección IP del host de la base de datos. Con esta información, los atacantes pueden conectarse a la base de datos y realizar acciones como agregar, modificar o eliminar contenidos de la base de datos.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-29 CVE Reserved
- 2024-04-29 CVE Published
- 2024-08-01 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
- CAPEC-37: Retrieve Embedded Sensitive Data
References (1)
URL | Tag | Source |
---|---|---|
https://www.twcert.org.tw/tw/cp-132-7774-fbd01-1.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
E-webinformationco Search vendor "E-webinformationco" | Fs-ezviewer Search vendor "E-webinformationco" for product "Fs-ezviewer" | * | - |
Affected
|