Skip to content

Known CVE

PrismaWEB - Credentials Disclosure

PrismaWEB is susceptible to credential disclosure. The vulnerability exists due to the disclosure of hard-coded credentials allowing an attacker to effectively bypass authentication of PrismaWEB with administrator privileges. The credentials can be disclosed by simply navigating to the login_par.js JavaScript page that holds the username and password for the management interface that are being used via the Login() function in /scripts/functions_cookie.js script.

CVE-2018-9161

Critical2018CVSS 9.8CWE-798

cve2018 · prismaweb · exposure · edb · prismaindustriale · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website