vendor:
PrismaWEB
by:
Gjoko 'LiquidWorm' Krstic
5.5
CVSS
MEDIUM
Authentication Bypass
CWE
Product Name: PrismaWEB
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: HMS AnyBus-S WebServer
2018
Prisma Industriale Checkweigher PrismaWEB 1.21 Authentication Bypass
The vulnerability exists due to the disclosure of hard-coded credentials allowing an attacker to effectively bypass authentication of PrismaWEB with administrator privileges. The credentials can be disclosed by simply navigating to the login_par.js JavaScript page that holds the username and password for the management interface that are being used via the Login() function in /scripts/functions_cookie.js script.