CVE-2020-21994

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
References
Configurations

Configuration 1

cpe:2.3:a:ave:dominaplus:*:*:*:*:*:*:*:*

Information

Published : 2021-04-28 03:15

Updated : 2022-10-26 03:15


NVD link : CVE-2020-21994

Mitre link : CVE-2020-21994

Products Affected
No products.
CWE