The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://itech-gmbh.de/#ueber-itech | product |
https://github.com/lisa-2905/CVE-2024-56428 | exploit third party advisory |