vendor:
LabVantage
by:
Joel Aviad Ossi
4.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: LabVantage
Affected Version From: LabVantage 8.3
Affected Version To: LabVantage 8.3
Patch Exists: NO
Related CWE: N/A
CPE: a:labvantage:labvantage:8.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: *
2020
LabVantage 8.3 – Information Disclosure
LabVantage 8.3 is vulnerable to an information disclosure vulnerability. An attacker can exploit this vulnerability by sending a specially crafted request to the target server. This request will return the database name and version of the LabVantage application, which can be used to further exploit the application.
Mitigation:
The vendor should ensure that the application does not disclose sensitive information to unauthorized users.