CVE-2024-6880
Severity CVSS v4.0:
MEDIUM
Type:
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
Publication date:
10/01/2025
Last modified:
10/01/2025
Description
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. <br />
Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks. <br />
<br />
This issue affects MegaBIP software versions below 5.15
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM