CVE-2020-7959 Information

Description

LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request because the response will return an ‘Unrecognized Database exception message if the database does not exist.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

https://github.com/websecnl/LabVantage8.3-Exploit https://www.exploit-db.com/exploits/48090

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

Share on: