Impact
A weakness in an unknown function of the backend/sxdevops/settings.py file allows an attacker to manipulate the file contents and cause exposure of sensitive configuration data. The flaw results in disclosure of confidential information that should not be publicly visible. The data exposed may include credentials, environment variables, or other secrets. The vulnerability is classified as Information Disclosure and is related to both CWE-200 (Sensitive Data Exposure) and CWE‑284 (Improper Access Control).
Affected Systems
The vulnerability affects aiyiyi121 SxDevOps 1.0 and 1.1. Users of these versions are at risk if the backend/sxdevops/settings.py file can be accessed or altered by an unauthorized party.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity impact. As the EPSS score is not available, there is no published exploitation probability, but the fact that the attack can be initiated remotely raises concern. The vulnerability is not listed in the CISA KEV catalog, which suggests no publicly known exploit targets, yet the remote nature of the attack vector increases the risk. Organizations should assume that an attacker could compromise confidentiality if the settings file is not adequately protected. Inferences: The attack can be performed from any remote host with network access to the server environment where SxDevOps is running. The precise exploitation steps are not detailed in the description, so the vector is inferred rather than explicitly stated.
OpenCVE Enrichment