CVE-2014-8940: Infoleak
Published Jun 1, 2020
·Updated
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.
Affected Software
1 affected component
piwigo Lexiglot<=2014-11-20
Event History
Jun 1, 2020
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of Lexiglot?
The vulnerability ID of Lexiglot is CVE-2014-8940.
2
What is the severity of CVE-2014-8940?
The severity of CVE-2014-8940 is medium with a severity value of 5.3.
3
How does CVE-2014-8940 impact Lexiglot?
CVE-2014-8940 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.
4
Which software versions are affected by CVE-2014-8940?
The Lexiglot software versions up to and including 2014-11-20 are affected by CVE-2014-8940.
5
Is there any available fix for CVE-2014-8940?
It is recommended to update to a newer version of Lexiglot that includes a fix for CVE-2014-8940.