Cynet 360 Web Portal before v4.5 exists to allow malicious users to access a list of decoy users via a crafted GET request sent to /WebApp/DeceptionUser/GetAllDeceptionUsers.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cynet cynet 360 |