MegaBIP Path Disclosure Vulnerability in Administrative Portal

Vulnerability

A path disclosure vulnerability has been identified in MegaBIP software versions prior to 5.15. During the installation process, users are advised to change the default administrative portal path, as keeping it secret is recommended for protection. However, the publicly available source code of '/registered.php' reveals this path, potentially allowing attackers to conduct further attacks.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the administrative portal, allowing attackers to perform actions with administrative privileges.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.