Zingiri Tickets <= 3.0.3 - Sensitive Information Disclosure
highThe Zingiri Tickets plugin for WordPress is vulnerable to Sensitive Data Exposure via the 'log.txt' file. This can allow unauthenticated attackers to extract sensitive data including Admin username and/or password hashes.
- CVSS:
- 7.5
- Affected:
- up to 3.0.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2012