WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack.
Score: 1.8
Priority: P4 - Informational (Low)
Score: 0.01174
Percentile:
0.77803
CVSS v2 Score: 5.0
Severity: