vendor:
SmartFoxServer 2X
by:
LiquidWorm
7.5
CVSS
HIGH
Credentials Disclosure
312
CWE
Product Name: SmartFoxServer 2X
Affected Version From: 2.17.0
Affected Version To: 2.17.0
Patch Exists: NO
Related CWE:
CPE: a:gotoAndPlay():smartfoxserver:2.17.0
Platforms Tested: Windows, Linux, MacOS, Java, Python
2021
SmartFoxServer 2X 2.17.0 – Credentials Disclosure
The application stores sensitive information in an unencrypted XML file called /config/server.xml. A local attacker that has access to the current user session can successfully disclose plain-text credentials that can be used to bypass authentication to the affected server.
Mitigation:
Encrypt sensitive information stored in the XML file. Implement proper access controls to prevent unauthorized access to the file.