Vulnerability Details CVE-2019-1010308
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2019-1010308
-
cpe:2.3:a:aquaverde:aquarius_cms:3.6.5
-
cpe:2.3:a:aquaverde:aquarius_cms:3.6.7
-
cpe:2.3:a:aquaverde:aquarius_cms:3.6.9
-
cpe:2.3:a:aquaverde:aquarius_cms:3.7.0
-
cpe:2.3:a:aquaverde:aquarius_cms:3.7.1
-
cpe:2.3:a:aquaverde:aquarius_cms:3.8.0
-
cpe:2.3:a:aquaverde:aquarius_cms:3.9.0
-
cpe:2.3:a:aquaverde:aquarius_cms:4.0.0
-
cpe:2.3:a:aquaverde:aquarius_cms:4.1.0