Medium
CVSS 5.0
Overview
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive informa...
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: