Critical vulnerability in the ownCloud plugin

A vulnerability has been detected in the graphapi plugin application: the URL "owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php" becomes accessible

This address triggers the phpinfo function, which reveals PHP configuration details. This information includes all environmental variables of the web server. In case of installation in a container, these variables may contain sensitive data such as the ownCloud administrator password, email credentials server and other information.

All system administrators are advised to delete the file "owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php", as well as update and change passwords.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster