Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Matomo | Matomo | * | 0.2.32 (including) |
Matomo | Matomo | 0.2.25 (including) | 0.2.25 (including) |
Matomo | Matomo | 0.2.26 (including) | 0.2.26 (including) |
Matomo | Matomo | 0.2.27 (including) | 0.2.27 (including) |
Matomo | Matomo | 0.2.28 (including) | 0.2.28 (including) |
Matomo | Matomo | 0.2.29 (including) | 0.2.29 (including) |
Matomo | Matomo | 0.2.30 (including) | 0.2.30 (including) |
Matomo | Matomo | 0.2.31 (including) | 0.2.31 (including) |