Back

HIGH

MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters

Published Feb 16, 2022

Description

MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters Attacker can navigate to specific url which will expose all the users and password in clear text. http://IP/MobiPlusWeb/Handlers/MainHandler.ashx?MethodName=GridData&GridName=Users

Affected products

Remediation

Vendor solution

An update was released which addresses the issue

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCD
Published Feb 16, 2022
Updated Sep 17, 2024
Reserved Jan 7, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a