Hidden and hard-coded credentials in ProLion CryptoSpike...
High severity
Unreviewed
Published
Dec 12, 2023
to the GitHub Advisory Database
•
Updated Dec 14, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 12, 2023
Last updated
Dec 14, 2023
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.
References