CVE-2022-35413

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:pentasecurity:wapples:*:*:*:*:*:*:*:*

Information

Published : 2022-09-13 15:15

Updated : 2022-09-30 19:28


NVD link : CVE-2022-35413

Mitre link : CVE-2022-35413


JSON object : View

CWE
CWE-798

Use of Hard-coded Credentials

Advertisement

dedicated server usa

Products Affected

pentasecurity

  • wapples