The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-09-20T07:54:53.890Z
Updated: 2023-09-20T07:54:53.890Z
Reserved: 2022-12-19T16:35:50.462Z
Link: CVE-2022-47561
JSON object: View
NVD Information
Status : Modified
Published: 2023-09-20T08:15:15.380
Modified: 2024-05-17T02:16:08.173
Link: CVE-2022-47561
JSON object: View
Redhat Information
No data.