UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' account names and passwords via this unprotected configuration file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
upspowercom upsmon pro 2.57 |