peter bassill · operator
$ cve CVE-2014-10079 JSON

CVE-2014-10079 EXPLOIT

5.3
MEDIUM · CVSS 3.0 · EPSS 8.7% (pctl 95)

Patch early

A public exploit exists.

Description

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.

Scoring

CVSS5.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS8.75% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2019-02-23
Last modified2026-06-17

Affected (1)

VendorProduct
vembustoregrid

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD