vendor:
Easy Chat Server
by:
Aitezaz Mohsin
9
CVSS
CRITICAL
Pre-Auth Remote Password Disclosure
200
CWE
Product Name: Easy Chat Server
Affected Version From: v2.0
Affected Version To: v3.1
Patch Exists: N/A
Related CWE: N/A
CPE: echatserver.com/ecssetup.exe
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Easy Chat Server Remote Password Disclosure
Registeration page 'register.ghp' allows disclosing ANY user's password. Remote un-authenticated attackers can send HTTP GET requests to obtain ANY Easy Chat Server user password.
Mitigation:
Ensure that the register.ghp page is not accessible to unauthenticated users.