Lack of data validation In piwik/piwik
Description
Piwik (now Matomo) Reveals Sensitive Information by Accepting Input from POST Requests
Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.11 | ||
packagist | 1.11 |
Aliases
1. 2. 3. 4.
References
1.