vendor:
ImageVue
by:
Sora
7.5
CVSS
HIGH
Remote Admin Login Exploit
287
CWE
Product Name: ImageVue
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:imagevue:imagevue:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows and Linux
2020
ImageVue 2.0 Remote Admin Login Exploit
ImageVue 2.0 suffers a remote admin login exploit. You can simply enter admin as the password and it will log you in as a global administrator.
Mitigation:
Enforce strong passwords and two-factor authentication for admin accounts.