Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
References
Link | Resource |
---|---|
https://gist.github.com/llandeilocymro/2438a0b5aba8b387c86d7e3181ecbe76 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-05-05 15:29
Updated : 2018-06-12 05:44
NVD link : CVE-2018-10723
Mitre link : CVE-2018-10723
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
rangerstudio
- directus