A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224240.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://vuldb.com/?id.224240 | permissions required vdb entry third party advisory technical description |
https://vuldb.com/?ctiid.224240 | permissions required signature third party advisory |
https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md | third party advisory exploit |