CVE-2024-31840

MEDIUM

Italtel Embrace 1.6.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web application fills the edit form with the current credentials for the email account, including the cleartext password.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-319 CWE-312
Status published
Products (1)
italtel/embrace 1.6.4
Published May 21, 2024
Tracked Since Feb 18, 2026