Description
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.
Remediation
References
Related Vulnerabilities
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.5)
WordPress Plugin Htaccess by BestWebSoft Cross-Site Request Forgery (1.8.1)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-15099)
Artifactory Missing Authorization Vulnerability (CVE-2019-10323)