ESAFENET CDG document management system targeted by login-bypass scanners following public XSS disclosure
Internet-wide scanning activity has been observed against ESAFENET's CDG document management platform, exploiting known weaknesses including default credentials, SQL injection, and cross-site scripting. The product, popular in Chinese markets, exhibits preventable authentication and input validation flaws despite being marketed as a secure data leakage prevention solution.