HIGH
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml
Published Mar 17, 2017
7.5
HIGHCVSS 3.0
EPSS 1.54%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.