CVE-2022-24581
02.06.2022, 14:15
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.Enginsight
Vendor | Product | Version |
---|---|---|
aceware | aceweb_online_portal | 𝑥 < 3.5.065 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration