Vulnerabilities > Matomo > Matomo > 3.9.1

DATE CVE VULNERABILITY TITLE RISK
2019-05-20 CVE-2019-12215 Information Exposure Through an Error Message vulnerability in Matomo 3.9.1
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig.
network
low complexity
matomo CWE-209
4.3