CVE-2022-27055

CVE-2022-27055

** DISPUTED ** ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the vendor disputes this because the environment file is in the data directory, which is not intended for access by website visitors (only the statics directory can be accessed by website visitors).

Source: CVE-2022-27055

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다