CVE-2023-50786

MEDIUM

Dradis <4.16.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

Scores

CVSS v3 4.1
EPSS 0.0016
EPSS Percentile 36.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-294
Status published
Products (1)
dradisframework/dradis < 4.16.0
Published Jul 05, 2025
Tracked Since Feb 18, 2026