Description
RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication.
Problem types
Exposure of Information Through Directory Listing
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5609.php (Zero Science Lab Disclosure (ZSL-2020-5609))
packetstormsecurity.com/files/160073 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/191803 (IBM X-Force Vulnerability Exchange)
cxsecurity.com/issue/WLB-2020110130 (CXSecurity Vulnerability Database)
www.red-v.tv/ (RED-V Vendor Homepage)
www.vulncheck.com/...og-information-disclosure-vulnerability (VulnCheck Advisory: RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability)