Medium
CVSS 5.0
Overview
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a...
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: