5
CVSSv2

CVE-2014-4311

Published: 04/11/2014 Updated: 05/11/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows malicious users to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

epicor epicor enterprise

Exploits

"Epicor Enterprise vulnerabilities" - Affected vendor: Epicor Software Corporation - Affected system: Epicor Enterprise - Version 74 - Vendor disclosure date: May 13th, 2014 - Public disclosure date: September 30th, 2014 - Status: Fixed - Associated CVEs: 1) CVE-2014-4311 Password values not masked appropriately: Even though the applica ...
Epicor suffers from cross site scripting and password disclosure vulnerabilities ...