Описание
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
Ссылки
- Third Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:anchorcms:anchor:0.12.3:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.9088
Критический
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
EPSS
Процентиль: 100%
0.9088
Критический
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200