Description
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Remediation
References
Related Vulnerabilities
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10673)
WordPress Plugin LearnDash LMS Insecure Direct Object Reference (4.6.0)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9855)
WordPress Improper Input Validation Vulnerability (CVE-2013-4339)