E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-04-29T03:31:40.592Z

Updated: 2024-08-01T20:33:53.219Z

Reserved: 2024-04-29T03:22:58.923Z

Link: CVE-2024-4300

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:53.219Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-29T04:15:08.887

Modified: 2024-04-29T12:42:03.667

Link: CVE-2024-4300

cve-icon Redhat

No data.