An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.
Weakness
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
References