CVE-2020-19137
08.09.2021, 21:15
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".Enginsight
Vendor | Product | Version |
---|---|---|
autumn_project | autumn | 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration