CVE-2020-23284
Last modified
CVE-2020-23284 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without logging into the web application.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals internal and sensitive information without logging into the web application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mv | Idce | 1.0 |
References
- https://github.com/ifmacedo/mconnect/blob/main/sensitiveDataExposureThird Party Advisory
- https://github.com/ifmacedo/mconnect/blob/main/sensitiveDataExposureThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-23284?
How severe is CVE-2020-23284?
How do I fix CVE-2020-23284?
Are you affected by CVE-2020-23284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
