CVE-2022-24581

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2022-06-02 14:15

Updated : 2022-06-02 14:53


NVD link : CVE-2022-24581

Mitre link : CVE-2022-24581


JSON object : View

Products Affected

No product.

CWE

No CWE.