The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-09-20T07:54:53.890Z
Updated: 2024-09-24T18:06:23.610Z
Reserved: 2022-12-19T16:35:50.462Z
Link: CVE-2022-47561
Vulnrichment
Updated: 2024-08-03T14:55:08.312Z
NVD
Status : Modified
Published: 2023-09-20T08:15:15.380
Modified: 2024-11-21T07:32:11.913
Link: CVE-2022-47561
Redhat
No data.