CVE-2018-14328
CRITICALBrynamics Online Trade - Info Disclosure
Title source: llmDescription
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms, as demonstrated by reading database username, database password, database_name, and IP address fields, related to CVE-2018-12908.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1704
EPSS Percentile
95.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-200
Status
published
Products (1)
brynamics/online_trade
Published
Jul 23, 2018
Tracked Since
Feb 18, 2026