Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (controlaccess.php-LAST) where database credentials are stored.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32281 | Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (controlaccess.php-LAST) where database credentials are stored. |
Fixes
Solution
The OpenGnsys development team has released a security patch that resolves the reported vulnerabilities. These fixes will be included in the next version to be released shortly.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opengnsys
Opengnsys opengnsys |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:opengnsys:opengnsys:1.1.1d:*:*:*:*:*:*:* | |
| Vendors & Products |
Opengnsys
Opengnsys opengnsys |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:20:00.914Z
Reserved: 2024-04-12T10:44:54.288Z
Link: CVE-2024-3706
Updated: 2024-08-01T20:20:00.914Z
Status : Analyzed
Published: 2024-04-12T14:15:09.160
Modified: 2025-11-04T18:15:46.883
Link: CVE-2024-3706
No data.
OpenCVE Enrichment
No data.
EUVD