CirCarLife before 4.3 is susceptible to improper authentication. An internal installation path disclosure exists due to the lack of authentication for /html/repository.System. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2018-16668
info:
name: CirCarLife <4.3 - Improper Authentication
author: geeknik
seve
...