Remote Information Disclosure in Lexiglot Plugin by Lexiglot Inc.
CVE-2014-8939

5.3MEDIUM

Key Information:

Vendor

Piwigo

Status
Vendor
CVE Published:
1 June 2020

What is CVE-2014-8939?

The Lexiglot plugin is susceptible to a remote information disclosure vulnerability that can allow remote attackers to obtain sensitive data, specifically the full server path. This issue arises when PHP is configured in a way that generates warning messages, which can be exploited by crafting specific requests to include/smarty/plugins/modifier.date_format.php. Users of Lexiglot should ensure that their PHP configurations follow recommended practices to mitigate exposure to such attacks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.