CVE-2014-2009

Publication date

2014-09-12 14:00:00

Family

mitre

State

PUBLISHED

Description

The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.