Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fay Stegerman

#30939of 53,632
8.4Total CVSS
Vulnerabilities · 1
PT-2025-5335
8.4
2025-01-20
Unknown · Writefreely · CVE-2025-24337
**Name of the Vulnerable Software and Affected Versions** WriteFreely versions 0.15.1 and earlier **Description** The issue allows local users to discover credentials by reading the config.ini file when MySQL is used. This is due to insecure default configuration access. **Recommendations** For versions 0.15.1 and earlier, consider restricting access to the config.ini file to prevent local users from discovering credentials. As a temporary workaround, limit read access to this file until a more permanent solution is available.