Description
This vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT.
Affected Versions
Remediation
Upgrade Kiteworks MFT to version 9.1.0 or later.
Acknowledgments
We thank xor-rax-rax for reporting this security vulnerability through our bug bounty program on bugcrowd.
Description
This vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT.
Affected Versions
Remediation
Upgrade Kiteworks MFT to version 9.1.0 or later.
Acknowledgments
We thank xor-rax-rax for reporting this security vulnerability through our bug bounty program on bugcrowd.