9.8

CVE-2018-7251

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AnchorcmsAnchor Version0.12.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 72.63% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://packetstormsecurity.com/files/154723/Anchor-CMS-0.12.3a-Information-Disclosure.html
http://www.andmp.com/2018/02/advisory-assigned-CVE-2018-7251-in-anchorcms.html
Third Party Advisory
https://github.com/anchorcms/anchor-cms/issues/1247
Third Party Advisory
Issue Tracking
https://github.com/anchorcms/anchor-cms/releases/tag/0.12.7
https://twitter.com/finnwea/status/965279233030393856