CVE-2017-15877

CRITICAL

GPWeb 8.4.61 - Unauthenticated Sensitive Information Exposure via db.php

Title source: llm
STIX 2.1

Description

Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.

Scores

CVSS v3 9.8
EPSS 0.0143
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
sistemagpweb/gpweb 8.4.61
Published Dec 19, 2017
Tracked Since Feb 18, 2026