Description
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.
Remediation
References
Related Vulnerabilities
Serendipity Other Vulnerability (CVE-2005-3129)
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.5.1)
Jenkins Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3666)
WordPress Plugin SP Project & Document Manager Multiple SQL Injection Vulnerabilities (2.4.3)