Vulnerability Description
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7774-fbd01-1.html
- https://www.twcert.org.tw/tw/cp-132-7774-fbd01-1.html
FAQ
What is CVE-2024-4300?
CVE-2024-4300 is a vulnerability with a CVSS score of 9.8 (CRITICAL). E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Acce...
How severe is CVE-2024-4300?
CVE-2024-4300 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-4300?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.