vendor:
Regulus
by:
Unknown
5.5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Regulus
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Information Disclosure in SAFE TEAM Regulus
An attacker can make a request for the 'staffile' file hosted on a target server in SAFE TEAM Regulus, which contains a list of 'staff' users and their corresponding password hashes. This information can be used to launch further attacks against the vulnerable software.
Mitigation:
Restrict access to the 'staffile' file and ensure proper access controls are in place. Regularly update the software to the latest version.