Vulnerabilities
Vulnerable Software
Damstratechnology:  Security Vulnerabilities
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-10-02
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.
CVSS Score
9.1
EPSS Score
0.268
Published
2020-10-02
An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").
CVSS Score
5.3
EPSS Score
0.005
Published
2020-10-02


Contact Us

Shodan ® - All rights reserved