In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a users cookie values and the predefined developers cookie value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
M3_atm_monitoring_system | Lanatmservice | 6.1.0 (including) | 6.1.0 (including) |