Lucene search

K
cvelistMitreCVELIST:CVE-2020-21994
HistoryApr 28, 2021 - 2:50 p.m.

CVE-2020-21994

2021-04-2814:50:56
mitre
www.cve.org
2
cve-2020-21994
ave dominaplus
clear-text credentials disclosure
unauthenticated attacker
xml file disclosure
administrative login information
authentication bypass

AI Score

9.6

Confidence

High

EPSS

0.145

Percentile

95.9%

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file ‘/xml/authClients.xml’ and obtain administrative login information that allows for a successful authentication bypass attack.

AI Score

9.6

Confidence

High

EPSS

0.145

Percentile

95.9%

Related for CVELIST:CVE-2020-21994