High
CVSS 7.5
Overview
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
Voodoo chat 1.0RC1b stores sensitive information under the web root with insuffi...
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
This vulnerability is rated 🟠 HIGH.
Recommended actions: