Creacast Creabox Manager 4.4.4 exposes sensitive...
High severity
Unreviewed
Published
Sep 22, 2025
to the GitHub Advisory Database
•
Updated Sep 23, 2025
Description
Published by the National Vulnerability Database
Sep 22, 2025
Published to the GitHub Advisory Database
Sep 22, 2025
Last updated
Sep 23, 2025
Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.
References