Information Disclosure Vulnerability in Kofax Front Office Server
CVE-2018-17287
4.9MEDIUM
What is CVE-2018-17287?
An information disclosure vulnerability exists in Kofax Front Office Server Administration Console versions up to 4.1.1.11.0.5212. This flaw allows an unauthorized user to retrieve sensitive data, including passwords, that are meant to be obfuscated in the user interface. By leveraging the back-end 'download' feature with operations like mfp.password downloadsettingvalue, cleartext values can be extracted, posing significant risks to data security.