CRITICAL9.8
GHSA-hxcw-pqqc-rv85
Anchor CMS Logs Credentials
Quick fix
GHSA-hxcw-pqqc-rv85 — anchorcms/anchor-cms: upgrade to the fixed version with the command below.
composer require anchorcms/anchor-cms:^0.12.7Details
An issue was discovered in `config/error.php` in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/anchorcms/anchor-cms
Introduced in:
0Fixed in: 0.12.7Fix
composer require anchorcms/anchor-cms:^0.12.7References
- https://nvd.nist.gov/vuln/detail/CVE-2018-7251[ADVISORY]
- https://github.com/anchorcms/anchor-cms/issues/1247[WEB]
- https://github.com/anchorcms/anchor-cms[PACKAGE]
- https://github.com/anchorcms/anchor-cms/releases/tag/0.12.7[WEB]
- https://twitter.com/finnwea/status/965279233030393856[WEB]
- http://packetstormsecurity.com/files/154723/Anchor-CMS-0.12.3a-Information-Disclosure.html[WEB]
- http://www.andmp.com/2018/02/advisory-assigned-CVE-2018-7251-in-anchorcms.html[WEB]