What the vulnerability does
01Description
Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.
Explanation of Vulnerability in Simple Terms
Debug Log Manager through version 2.3.1 fails to properly restrict access to sensitive debug log files. An authenticated user with low privileges can read debug logs that should be restricted to administrators, potentially exposing sensitive configuration data, database credentials, or other system information stored in those logs.
What an attacker can do
Read debug log files containing sensitive system and configuration information.
Potential impact on your site
Sensitive debug logs may be exposed to any authenticated user, risking disclosure of credentials or system details.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities