Description
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.
Remediation
References
Related Vulnerabilities
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-5702)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.12)
MySQL CVE-2019-2950 Vulnerability (CVE-2019-2950)
WordPress Plugin WP Rss Poster SQL Injection (1.0.0)
WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02)