What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.
Explanation of Vulnerability in Simple Terms
The 404 Solution product through version 2.33.0 contains an insertion of sensitive information into log files. An attacker with network access can read log files to obtain sensitive data that should not be logged. No authentication or user interaction is required. Site administrators should update to a version newer than 2.33.0.
What an attacker can do
Read sensitive information from application log files without authentication.
Potential impact on your site
Sensitive data may be exposed in log files accessible to attackers or unauthorized users.
Conditions required to exploit
Network access to the application; no authentication required.
Key dates
External resources
Related vulnerabilities