vendor:
eFramework
by:
elbae
9.8
CVSS
CRITICAL
Back Door Access
287
CWE
Product Name: eFramework
Affected Version From: <= 2.9.0
Affected Version To: <= 2.9.0
Patch Exists: YES
Related CWE: CVE-2020-15921
CPE: 2.9.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Mida eFramework 2.9.0 – Back Door Access
This script can be used to retrieve the code which gives you the possibility to change the password. How it works: 1) run the script 2) copy the output to the URL you want to access (i.e. http://192.168.1.60:8090/PDC/extreq.php?code=THE-CODE) 3) change the password 4) access as admin with the password
Mitigation:
Ensure that the application is updated to the latest version and that all security patches are applied.