CVE Vulnerabilities

CVE-2024-32236

Insecure Storage of Sensitive Information

Published: Apr 25, 2024 | Modified: Jul 03, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

References