CVE-2018-20465

7.2
HIGHCVSS v3.1 Base Score
1.53%
LOW RiskEPSS (74th percentile)

Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.

Published: 12/25/2018
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.2HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

4

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

1.53%LOW Exploitation Risk
74th percentile

This vulnerability has a 1.53% probability of being exploited in the next 30 days, ranking higher than 74% of all scored CVEs.

CWE Classification

Advertisement