Description
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without logging into the web application.
References
https://github.com/ifmacedo/mconnect/blob/main/sensitiveDataExposure
Third Party Advisory
https://github.com/ifmacedo/mconnect/blob/main/sensitiveDataExposure
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-07-20T18:15:07.543Z
4 years agoLast modified
2024-11-21T04:13:42.720Z
1 year ago