Description
Magento stores its configuration in a file local.xml. Due to a misconfiguration of a web server, an attacker can access the cofiguration file.
Remediation
Restrict access to local.xml
References
Related Vulnerabilities
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7484)
WordPress Plugin Shopping Cart & eCommerce Store Information Disclosure (2.0.5)
WordPress Plugin Memphis Documents Library Arbitrary File Download (3.1.5)
ZK Framework AuUploader Information Disclosure (CVE-2022-36537)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5730)