CVE-2024-6880: Jan Syski Megabip

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.   This issue affects MegaBIP software versions below 5.15

Affected products

  • Jan Syski Megabip: before 5.15 (fixed in 5.15)

Published 2025-01-10. Last modified 2026-06-17.