Description
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
Problem types
Generation of Error Message Containing Sensitive Information
Product status
Credits
TickTackk
References
xenforo.com/...-3-7-released-includes-security-fixes.232121/ (XenForo 2.3.7 Released (Includes Security Fixes))
www.vulncheck.com/...-disclosure-via-open-basedir-exceptions (VulnCheck Advisory: XenForo Path Disclosure via open_basedir Exceptions)