Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.exploit-db.com/exploits/9493 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52724 | vdb entry |