vendor:
Matrix MLM Script
by:
Ihsan Sencan
3.3
CVSS
MEDIUM
Information Leakage
200
CWE
Product Name: Matrix MLM Script
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:royallifefoundation:matrix_mlm_script:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Matrix MLM Script 1.0 – Information Leakage
Matrix MLM Script 1.0 is vulnerable to Information Leakage. An attacker can send a GET request to the getdata.php page in the modules directory to view sensitive information such as userid, username, profileid, passport, currentstage, l_member, r_member, firstname, lastname, emailaddress, and parentid.
Mitigation:
Ensure that the application is not exposing any sensitive information to unauthorized users.