CVE Vulnerabilities

CVE-2021-36544

Insertion of Sensitive Information into Log File

Published: Feb 03, 2023 | Modified: Mar 26, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
TpcmsTpcms_project3.2 (including)3.2 (including)

Potential Mitigations

References