TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrators user name and password.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tpcms | Tpcms_project | 3.2 (including) | 3.2 (including) |