What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a through 1.4.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a through 1.4.5.
Explanation of Vulnerability in Simple Terms
Debug Log – Manager Tool versions up to 1.4.5 expose sensitive log file contents to unauthenticated attackers over the network. The tool fails to restrict access to debug logs, allowing anyone to read potentially sensitive information without authentication. Update to a version newer than 1.4.5 to resolve this issue.
What an attacker can do
Read sensitive debug log files without authentication.
Potential impact on your site
Attackers can access debug logs containing sensitive data like credentials, API keys, or system details.
Conditions required to exploit
Network access to the tool; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities