Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightmeter instance to access application settings, possibly including an SMTP password and a Slack access token, via a settings HTTP query.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-04-02T19:36:08

Updated: 2024-08-03T22:24:59.425Z

Reserved: 2021-04-02T00:00:00

Link: CVE-2021-30126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-02T20:15:13.597

Modified: 2024-11-21T06:03:21.487

Link: CVE-2021-30126

cve-icon Redhat

No data.