Directory Browsing Vulnerability in MCL-Net Webserver by MCL Collection
CVE-2023-34834

5.3MEDIUM

Key Information:

Vendor
CVE Published:
29 June 2023

What is CVE-2023-34834?

The MCL-Net webserver version 4.3.5.8788 is susceptible to a Directory Browsing vulnerability. This flaw permits attackers to access sensitive information regarding configured databases by exploiting the '/file' endpoint. This could lead to unauthorized data exposure, enhancing the risk of further attacks if sensitive data is leaked.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.