CRITICAL
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack
Published Apr 28, 2021
9.8
CRITICALCVSS 3.1
EPSS 3.66%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.