GHSA-hxcw-pqqc-rv85
Dashboard / Vulnerabilities / GHSA-hxcw-pqqc-rv85
Summary: Anchor CMS Logs Credentials
Details: An issue was discovered in `config/error.php` in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-7251, https://github.com/anchorcms/anchor-cms/issues/1247, https://github.com/anchorcms/anchor-cms, https://github.com/anchorcms/anchor-cms/releases/tag/0.12.7, https://twitter.com/finnwea/status/965279233030393856, http://packetstormsecurity.com/files/154723/Anchor-CMS-0.12.3a-Information-Disclosure.html, http://www.andmp.com/2018/02/advisory-assigned-CVE-2018-7251-in-anchorcms.html
Affected packages
Package
Name: anchorcms/anchor-cms
Purl: pkg:composer/anchorcms/anchor-cms
Affected ranges
Type: ECOSYSTEM
Events:
