CVE Vulnerabilities

CVE-2024-39776

Storage of File with Sensitive Data Under Web Root

Published: Aug 22, 2024 | Modified: Sep 04, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Weakness

The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.

Affected Software

NameVendorStart VersionEnd Version
Outpost_uploader_utilityAvtecinc*5.0.0 (excluding)

Potential Mitigations

References