Beveiligingsadvies

CVE-2017-1000192

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-11-17 17:00:00
Laatst bijgewerkt 2024-09-16 20:36:28
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.