vendor:
Xataface
by:
Xinapse
8,8
CVSS
HIGH
Admin/database auth bypass vulnerability
N/A
CWE
Product Name: Xataface
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Xataface Admin Auth Bypass Vulnerability
With this exploit, an attacker can edit/delete/create records in the database, create new admin accounts and view all the users and passwords.
Mitigation:
Using .htaccess to restrict access to the admin page.