School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrator credentials.
Solution:
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-8415-853e0-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-8416-b6cba-2.html | third party advisory |