漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Error Handling Leading to Sensitive Information Disclosure in CIGES ≤ 2.15.6
Vulnerability Description
A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose internal filesystem paths, SQL queries, database connection details, or environment configuration data to remote unauthenticated attackers. This issue allows information gathering and reconnaissance but does not enable direct system compromise.
CVSS Information
N/A
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
ATISoluciones CIGES 安全漏洞
Vulnerability Description
ATISoluciones CIGES是西班牙ATISoluciones公司的一个预约排队管理系统。 ATISoluciones CIGES 2.15.6及之前版本存在安全漏洞,该漏洞源于错误处理组件返回详细错误信息,可能导致敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A