SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-4148

Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the…

MEDIUM 5.0EPSS 1.78%

Does this matter?

Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.

Description

Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.78% probability · 77th percentile
CISA KEV
Not listed
Affected
lyris technologies inc/listmanager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.