Medium
CVSS 5.0
Overview
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.
User Engine Lite ASP stores sensitive information under the web root with insuff...
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: