vendor:
Mongo Web Admin
by:
Ihsan Sencan
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Mongo Web Admin
Affected Version From: 6.0
Affected Version To: 6.0
Patch Exists: NO
Related CWE: N/A
CPE: a:mongoadmin:mongo_web_admin:6.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Mongo Web Admin 6.0 – Information Disclosure
Mongo Web Admin 6.0 is vulnerable to information disclosure. An attacker can send a GET request to the webservice/Data/connections.json endpoint to view the connection details such as host, port, user, and password.
Mitigation:
Ensure that the webservice/Data/connections.json endpoint is not publicly accessible.