What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
Explanation of Vulnerability in Simple Terms
Subscribe To Comments Reloaded contains an insertion of sensitive information into log files. An unauthenticated attacker on the network can read log entries containing user data without special privileges or user interaction. The vulnerability affects versions up to 220725. Update to a version newer than the affected range.
What an attacker can do
Read sensitive user information written to log files accessible over the network.
Potential impact on your site
User data may be exposed in log files readable by attackers without site access.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities