Sensitive Information Exposure in Lexiglot by Piwigo
CVE-2014-8940

5.3MEDIUM

Key Information:

Vendor

Piwigo

Status
Vendor
CVE Published:
1 June 2020

What is CVE-2014-8940?

Lexiglot software versions up to November 20, 2014, contain a vulnerability that permits remote attackers to access sensitive information, including project names and details, simply by navigating to the /update.log URI. This exposure can potentially lead to further exploitation due to the information disclosed, emphasizing the need for prompt remediation to protect user data.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.