Description
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
Problem types
CWE-215 Insertion of Sensitive Information Into Debugging Code
Product status
Any version before 3.7.7
Credits
Alex Williams of Converge Technology Solutions
References
jvn.jp/en/vu/JVNVU92266386/
www.vulncheck.com/...rosys-hmi-system-exposed-php-debug-info