Sensitive Information Disclosure in User Creation Feature of Devolutions Remote Desktop Manager

Sensitive Information Disclosure in User Creation Feature of Devolutions Remote Desktop Manager

CVE-2023-1574 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.

Learn more about our Cis Benchmark Audit For Desktop Software.