An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Cipace | Cipplanner | * | 9.1 (excluding) |
References