rodolfomarianocy/xpl-ModernWMS-CVE-2024-57698

rodolfomarianocy/xpl-ModernWMS-CVE-2024-57698

Releases0
It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change. This is due to excessive information exposure, lack of session management, and inadequate access control on the /user/list?culture=en-us endpoint.

Collections containing this project

Showing collections based on your access.

This project is not in any collections you can view.