Back to search
CVE-2024-6880
Published: Jan 10, 2025
Modified: Jan 10, 2025
PUBLISHED
Description
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks. This issue affects MegaBIP software versions below 5.15
| Vendor | Product | Versions |
|---|---|---|
Jan Syski | MegaBIP | affected 0 - < 5.15 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now