|
JAF CMS contains a flaw that may lead to an unauthorized disclosure. The issue is triggered when the index.php script is passed certain invalid input to the "id" parameter, which will disclose the product's installation path, resulting in a loss of confidentiality.
|