CVE-2025-24337 Details
Description
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
A vulnerability in WriteFreely versions through 0.15.1 allows local users to access MySQL database credentials stored in plaintext within a world-readable config.ini file. This issue arises when WriteFreely is set up to use a MySQL database, following the standard installation instructions. The vulnerability is present on any Linux-based platform, and potentially others, affecting instances on shared hosting environments.
WriteFreely administrators should immediately restrict the permissions of the config.ini file to make it readable only by the file owner. After adjusting the permissions, it's important to monitor the file regularly, especially after using WriteFreely's console tools, which can inadvertently reset the file permissions to a more permissive state.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 20, 2025CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/writefreely/writefreely/releases/tag/v0.15.1 | [email protected] | Release NotesVendor |
| https://raphus.social/@TV4Fun/113846757112643161 | [email protected] | ExploitTechnical Description |
| https://www.openwall.com/lists/oss-security/2025/01/18/1 | [email protected] | Mailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WriteFreely | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 20, 2025 | New CVE Received | [email protected] |
Volerion