What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.
Explanation of Vulnerability in Simple Terms
User Spam Remover version 1.0 and earlier logs sensitive information in a way that can be accessed without authentication. An attacker on the network can read this logged data, potentially exposing user details or system information. Update to a version newer than 1.0 if available from the vendor.
What an attacker can do
Read sensitive logged information without needing to log in to the site.
Potential impact on your site
User data or system details logged by the plugin may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities