CVE-2020-21994
CRITICALAVE DOMINAplus <=1.10.x - Unauthenticated Credential Disclosure via /xml/authClients.xml
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-21994. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit discloses credentials by fetching an unprotected XML file (`/xml/authClients.xml`) from AVE DOMINAplus systems, allowing unauthenticated access to administrative login information. It parses the XML to extract usernames and passwords.
Description
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
Exploits (1)
This exploit discloses credentials by fetching an unprotected XML file (`/xml/authClients.xml`) from AVE DOMINAplus systems, allowing unauthenticated access to administrative login information. It parses the XML to extract usernames and passwords.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H