Vulnerability: Information Leakage via Error Page in Yakamara Media Redaxo CMS 5.12.1

Vulnerability: Information Leakage via Error Page in Yakamara Media Redaxo CMS 5.12.1

CVE-2021-39458 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

Learn more about our Cms Pen Testing.