FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat.
| Software | From | Fixed in |
|---|---|---|
| freestyle / freestyle_wiki | - | 3.6.2.x |