Cleartext Storage of Sensitive Information
CVE-2018-8947
Summary
rap2hpoutre Laravel Log Viewer through v0.12.0 relies on Base64 encoding for "l", "dl", and "del" requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a "dl" request.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-312 - Cleartext Storage of Sensitive Information
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
References
Advisory Timeline
- Published