Medium
CVSS 5.0
Overview
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive informati...
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: