
Remote attacker can access sensitive data exposed on the URL
In DonWeb Ferozo Hosting v1.1, a remote attacker can exploit URL parameters to access sensitive data, including database credentials. Attack vectors include network sniffing, server logs, and browser history, potentially exposing organizations to major security breaches and data protection violations. Mitigating with HTTPS and secure logging practices is essential.
CVE-2024-50961
Reported by [Facundo Fernandez / Security Researcher]