Description
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.
Remediation
References
Related Vulnerabilities
WordPress Plugin Author Stats Cross-Site Scripting (1.3)
WordPress Plugin Vuukle Comments, Reactions, Share Bar, Revenue Unspecified Vulnerability (4.0.2)
Joomla! Core 3.x.x Security Bypass (3.2.0 - 3.4.4)
Vanilla Forums Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2018-15833)