CMS Information Disclosure
Unknown
Vulnerability Details
Hi,
I noticed that the CHANGELOG.txt disclose Drupal vesion. It might help an attacker to perform information gathering and help an attacker to find the vulnerabilties from the version.
PoC:
https://staging.uzbey.com/CHANGELOG.txt
Actions
View on HackerOneReport Stats
- Report ID: 17297
- State: Closed
- Substate: resolved
- Upvotes: 3