An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-18T20:00:00

Updated: 2018-10-04T19:57:01

Reserved: 2018-09-07T00:00:00


Link: CVE-2018-16669

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-18T20:29:01.030

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-16669

JSON object: View

cve-icon Redhat Information

No data.

CWE