What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.
Explanation of Vulnerability in Simple Terms
Backup Migration versions up to 1.4.3 expose sensitive information through improper access controls. An unauthenticated attacker can read backup files and configuration data over the network without user interaction. The vulnerability allows disclosure of private site data but does not permit modification or service disruption. Update to a version newer than 1.4.3.
What an attacker can do
Read backup files and sensitive configuration data without authentication.
Potential impact on your site
Backup files containing database dumps, user data, and configuration may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the affected Backup Migration installation; no authentication required.
Key dates
External resources
Related vulnerabilities