Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgx4-mfw2-ccw7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

EPSS

Процентиль: 56%
0.00332
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

EPSS

Процентиль: 56%
0.00332
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-522