A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224240.
References
Link | Resource |
---|---|
https://vuldb.com/?ctiid.224240 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.224240 | Permissions Required Third Party Advisory |
https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md | Exploit Third Party Advisory |
Configurations
History
15 May 2023, 19:26
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:xunruicms:xunruicms:4.6.1:*:*:*:*:*:*:* |
05 Apr 2023, 01:57
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://vuldb.com/?ctiid.224240 - Permissions Required, Third Party Advisory | |
References | (MISC) https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md - Exploit, Third Party Advisory | |
References | (MISC) https://vuldb.com/?id.224240 - Permissions Required, Third Party Advisory | |
CWE | CWE-312 | |
First Time |
Xunruicms
Xunruicms xunruicms |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:xunruicms:xunruicms:4.61:*:*:*:*:*:*:* |
Information
Published : 2023-03-29 01:15
Updated : 2024-05-17 02:18
NVD link : CVE-2023-1683
Mitre link : CVE-2023-1683
JSON object : View
Products Affected
xunruicms
- xunruicms
CWE
CWE-312
Cleartext Storage of Sensitive Information