Nway Pro Argument index.php ajax_login_submit_form information exposure
Published Feb 29, 2024
7.5
HIGHCVSS 3.1
EPSS 0.62%
Description
A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file login\index.php of the component Argument Handler. The manipulation of the argument rsargs[] leads to information exposure through error message. The attack may be launched remotely. VDB-255266 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
- Vendor n/a Product Nway Pro Defaultn/a
- Version 9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Nway Pro | n/a |
|
-
- Version 9StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://vuldb.com/?ctiid.255266 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.255266 vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://vuldb.com/?ctiid.255266 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.255266 | vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.