F-logic DataCube3 v1.0 is vulnerable to Incorrect Access...
Critical severity
Unreviewed
Published
Feb 29, 2024
to the GitHub Advisory Database
•
Updated Aug 13, 2024
Description
Published by the National Vulnerability Database
Feb 29, 2024
Published to the GitHub Advisory Database
Feb 29, 2024
Last updated
Aug 13, 2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.
References