Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
Threat-Mapped Scoring
Score: 3.0
Priority: P2 - Serious (High)
S1 – Steal Customer Account Information
EPSS
Score: 0.05261 Percentile:
0.89551
CVSS Scoring
CVSS v2 Score: 5.0
Severity:
Mapped CWE(s)
CWE-552
: Files or Directories Accessible to External Parties
All CAPEC(s)
CAPEC-150: Collect Data from Common Resource Locations
CAPEC-639: Probe System Files
CAPEC(s) with Mapped TTPs
CAPEC-150: Collect Data from Common Resource Locations
Mapped TTPs: