336 – Business information leak - Corporate information
Description
It is possible to access information about some of the company employees, such as their roles and contact information.
Impact
Obtain information about the role played by some workers within the company. As well as their contact information.
Recommendation
Establish controls to prevent an attacker from accessing the organizations corporate information.
Threat
Attacker with access to the application from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X