Impact
Manipulation of the DB_DEBUG argument in light0011 CMS’s config.php file allows remote attackers to access configuration information. The vulnerability arises from improper handling of this parameter during a debugging operation, exposing internal configuration details that are not intended for public disclosure. Because the flaw is triggered via an HTTP request, an attacker can potentially learn sensitive database credentials, file paths, or other configuration settings, which could facilitate further compromise. The CVSS score of 6.9 indicates a moderate severity and reflects the risk of information exposure and possible privilege escalation through exposed configuration data.
Affected Systems
The affected product is light0011 CMS, with no specific version or release information available due to the project’s rolling release model. All installations of the CMS that include the Debug Mode component and expose the configuration file are potentially vulnerable. The absence of version data means that any active deployment of light0011 CMS remains at risk until a patch or disabling of debug mode is performed.
Risk and Exploitability
The vulnerability can be exploited remotely by sending requests that modify the DB_DEBUG argument, and the vulnerability is publicly documented with available proof‑of‑concept references. Although the EPSS score is not available, the publicly disclosed exploit indicates a realistic likelihood of exploitation. The CVSS score of 6.9 places this in the moderate range, yet the potential to disclose sensitive configuration data elevates the overall risk. The vulnerability is not listed in the CISA KEV catalog, which suggests it has not yet been widely used in known attacks, but the already available exploit files mean that mitigation should be urgent.
OpenCVE Enrichment