Medium
CVSS 5.0
Overview
validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.
validate.php in WebCalendar allows remote attackers to gain sensitive informatio...
validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: