Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the name URL parameter.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
5n2_firmware | Drobo | 4.0.5-13.28.96115 (including) | 4.0.5-13.28.96115 (including) |