296,172
Total vulnerabilities in the database
When accessing the install.php
script it is possible to extract any pre-configured database or default admin account password by viewing the source of the page, and inspecting the value
property of the password fields.
Software | From | Fixed in |
---|---|---|
![]() |
4.0.0-rc1 | 4.0.1 |