SB2023072543 - Information disclosure in EyouCMS
Published: July 25, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2023-37645)
The vulnerability allows a remote attacker to obtain sensitive information.
The vulnerability exists due to improper access restrictions in the /eyoucms/data/model/custom_model_path/recruit.filelist.txt. A remote attacker can bypass implemented security restrictions and gain unauthorized access to sensitive indoemation on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.