vendor:
Online Trade Online Forex and Cryptocurrency Investment System
by:
L0RD
9.8
CVSS
CRITICAL
Information Disclosure
200
CWE
Product Name: Online Trade Online Forex and Cryptocurrency Investment System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2018-12908
CPE: a:codecanyon:online_trade_online_forex_and_cryptocurrency_investment_system:1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10
2018
Online Trade 1 – Information Disclosure
Online trading and cryptocurrency investment system 1 allows information disclosure by appending /dashboard/deposit. The following path contains database credentials and other information (username , password , database_name etc).
Mitigation:
Ensure that the application does not disclose sensitive information in the response.