Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://deathflash1411.github.io/blog/dumping-batflat-cms-database | broken link |
https://github.com/sruupl/batflat/issues/113 | third party advisory issue tracking |