Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-56902. PoCs published by Giorgi Dograshvili, DRAGOWN.
AI-analyzed exploit summary The exploit demonstrates an information disclosure vulnerability in GeoVision GV-ASManager (v6.1.0.0 or less) by sending a crafted POST request to retrieve all user accounts and their cleartext passwords. It requires low-privilege access (e.g., Guest account) and leverages the 'UA_GetAllUserAccount' action in the ASWebCommon.srf endpoint.
Description
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
Exploits (2)
The exploit demonstrates an information disclosure vulnerability in GeoVision GV-ASManager (v6.1.0.0 or less) by sending a crafted POST request to retrieve all user accounts and their cleartext passwords. It requires low-privilege access (e.g., Guest account) and leverages the 'UA_GetAllUserAccount' action in the ASWebCommon.srf endpoint.
This repository documents CVE-2024-56902, an information disclosure vulnerability in Geovision GV-ASManager v6.1.0.0 or earlier, allowing low-privilege accounts to retrieve cleartext passwords of any user. The writeup includes steps to exploit the vulnerability and its impact.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N