aquaverde/aquarius-core

aquaverde/aquarius-core

Releases14
Frequency5 months 2 weeks
Last Release
Stars2
aquarius CMS

CVE History

CVEPublishedCVSS v3CVSS v2
5 MEDIUM

Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.

5 MEDIUM

Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances.