CVE-2023-50786

MEDIUM

Dradis <4.16.0 - Info Disclosure

Title source: llm

Description

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

Scores

CVSS v3 4.1
EPSS 0.0004
EPSS Percentile 10.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Classification

CWE
CWE-294
Status published

Affected Products (1)

dradisframework/dradis < 4.16.0

Timeline

Published Jul 05, 2025
Tracked Since Feb 18, 2026