An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Cipace |
Cipplanner |
* |
9.1 (excluding) |
References