CVE-2019-19021

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
02/12/2019
Last modified:
09/12/2019

Description

An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:titanhq:webtitan:*:*:*:*:*:*:*:* 5.18 (excluding)