AI description
CVE-2026-84149 is an information disclosure vulnerability found in the Manacle Technologies Multi-tenant ERP System. This flaw stems from a publicly accessible `.git` directory located on the application's web server. An unauthenticated, remote attacker can exploit this vulnerability by accessing the exposed `.git` directory. This allows them to browse or download the repository metadata, which can then be used to reconstruct parts of the application's source code. Such an exposure could potentially reveal sensitive data, including embedded credentials, API keys, and internal application logic. The vulnerability is categorized under CWE-527, which refers to the exposure of a version-control repository to an unauthorized control sphere.
- Description
- This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.
- Source
- vdisclose@cert-in.org.in
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- vdisclose@cert-in.org.in
- CWE-527
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
26