CVE-2020-21997
HIGHSmartwares HOME easy <=1.0.9 - Unauthenticated Database Backup Download and Information Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-21997. PoCs published by LiquidWorm.
AI-analyzed exploit summary This script exploits an unauthenticated database backup disclosure vulnerability in Smartwares HOME easy <=1.0.9. It downloads the SQLite database, extracts credentials, version info, and active sessions.
Description
Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information resulting in authentication bypass, session hijacking and full system control.
Exploits (1)
This script exploits an unauthenticated database backup disclosure vulnerability in Smartwares HOME easy <=1.0.9. It downloads the SQLite database, extracts credentials, version info, and active sessions.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N