Back

HIGH

Insertion of Sensitive Information into Externally-Accessible File or Directory in BVRP Software SLmail

Published Nov 23, 2023

Description

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

Affected products

Remediation

Vendor solution

There is no reported solution at the moment.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Nov 23, 2023
Updated Aug 2, 2024
Reserved Aug 29, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a