Vulnerability CVE-2020-7959


Published: 2020-02-17   Modified: 2020-02-18

Description:
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Labvantage -> Labvantage 

 References:
https://github.com/websecnl/LabVantage8.3-Exploit
https://www.exploit-db.com/exploits/48090

Copyright 2024, cxsecurity.com

 

Back to Top