An information exposure vulnerability has been found, the...
High severity
Unreviewed
Published
Nov 23, 2023
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Nov 23, 2023
Published to the GitHub Advisory Database
Nov 23, 2023
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.
References