Description
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.
Remediation
References
Related Vulnerabilities
PHP Incorrect Calculation of Buffer Size Vulnerability (CVE-2025-1861)
WordPress Plugin ByREV WP-PICShield Cross-Site Request Forgery (1.9.7)
WordPress Plugin Simple Fields Cross-Site Scripting (1.4.11)
Moodle Exposure of Sensitive Information Through Metadata Vulnerability (CVE-2025-26527)
Spring Cloud Gateway Improper Certificate Validation Vulnerability (CVE-2022-22946)