Description
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2017-8511 Vulnerability (CVE-2017-8511)
WebLogic CVE-2019-2658 Vulnerability (CVE-2019-2658)
MySQL CVE-2022-21595 Vulnerability (CVE-2022-21595)
WordPress Plugin Constant Contact for WordPress Unspecified Vulnerability (3.1.6)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-1941)