First published: Thu Apr 18 2019(Updated: )
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kofax Front Office Server | =4.1.1.11.0.5212 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.