Incomplete in the CWE catalog · 1 CVE mapped
The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.
The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.