A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/matomo-org/matomo/issues/14464 |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:17:38.910Z
Reserved: 2019-05-20T00:00:00.000Z
Link: CVE-2019-12215
No data.
Status : Modified
Published: 2019-05-20T16:29:01.320
Modified: 2024-11-21T04:22:26.380
Link: CVE-2019-12215
No data.
OpenCVE Enrichment
No data.
Weaknesses