CVE Database
/

CVE-2024-6880

Back to search

CVE-2024-6880

Published: Jan 10, 2025

Modified: Jan 10, 2025

PUBLISHED

Description

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.   This issue affects MegaBIP software versions below 5.15

VendorProductVersions

Jan Syski

MegaBIP

affected
0 - < 5.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now