vendor:
Home Easy
by:
LiquidWorm
4.3
CVSS
MEDIUM
Information Disclosure and Client-Side Authentication Bypass
200
CWE
Product Name: Home Easy
Affected Version From: <=1.0.9
Affected Version To: <=1.0.9
Patch Exists: NO
Related CWE: N/A
CPE: a:smartwares:home_easy
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Boa/0.94.13
2019
Smartwares HOME easy 1.0.9 – Client-Side Authentication Bypass
HOME easy suffers from information disclosure and client-side authentication bypass vulnerability through IDOR by navigating to several administrative web pages. This allowed disclosing an SQLite3 database file and location. Other functionalities are also accessible by disabling JavaScript in your browser, bypassing the client-side validation and redirection.
Mitigation:
Ensure that client-side authentication is properly implemented and enforced.