Description
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.
Remediation
References
Related Vulnerabilities
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10321)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.1)
Drupal Improper Input Validation Vulnerability (CVE-2010-2473)
Liferay Portal Observable Discrepancy Vulnerability (CVE-2024-26268)
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-15882)