Medium
CVSS 5.0
Overview
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb.
Cold BBS stores sensitive information under the web root with insufficient acces...
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: