What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.
Explanation of Vulnerability in Simple Terms
Solid Affiliate through version 1.9.1 exposes sensitive information due to improper access controls. An attacker can read private data without authentication by making direct requests to the application. The vulnerability affects confidentiality but not data integrity or availability. Site administrators should update to a version newer than 1.9.1.
What an attacker can do
Read sensitive information without logging in.
Potential impact on your site
Attackers can access private data stored by the plugin without needing a user account.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities