Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.s3.eurecom.fr/cve/CVE-2014-3928.txt | third party advisory |
https://github.com/Cougar/lg/issues/4 | issue tracking third party advisory patch |
https://hackerone.com/reports/16330 | third party advisory |