Web services managed by Edito CMS (Content Management...
High severity
Unreviewed
Published
Jul 2, 2024
to the GitHub Advisory Database
•
Updated Jul 2, 2024
Description
Published by the National Vulnerability Database
Jul 2, 2024
Published to the GitHub Advisory Database
Jul 2, 2024
Last updated
Jul 2, 2024
Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user.
The issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January 2014. Higher versions were never affected.
References