Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/47107https://www.exploit-db.com/exploits/7348