CVE-2024-6880

Severity CVSS v4.0:
MEDIUM
Type:
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
Publication date:
10/01/2025
Last modified:
10/01/2025

Description

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. <br /> Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.  <br /> <br /> This issue affects MegaBIP software versions below 5.15