Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://www.synck.com/blogs/news/newsroom/detail_1745302910.html | product |
https://jvn.jp/en/jp/JVN39546799/ | third party advisory |