Skip to main content

Cleartext Storage of Sensitive Information

CVE-2018-8947

Severity High
Score 7.5/10

Summary

rap2hpoutre Laravel Log Viewer through v0.12.0 relies on Base64 encoding for "l", "dl", and "del" requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a "dl" request.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-312 - Cleartext Storage of Sensitive Information

The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Advisory Timeline

  • Published