← Back to CVE List

CVE-2024-39341

Published: 2024-09-23T18:15Z
Last Modified: 2024-11-04T17:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct IIS webroot path. It includes system configuration parameter names and values with sensitive configuration values encrypted. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt