Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days