During MegaBIP installation process, a user is encouraged...
Moderate severity
Unreviewed
Published
Jan 10, 2025
to the GitHub Advisory Database
•
Updated Jan 10, 2025
Description
Published by the National Vulnerability Database
Jan 10, 2025
Published to the GitHub Advisory Database
Jan 10, 2025
Last updated
Jan 10, 2025
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.
Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.
This issue affects MegaBIP software versions below 5.15
References