CVE Vulnerabilities

CVE-2024-32236

Insecure Storage of Sensitive Information

Published: Apr 25, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

References