CVE-2026-30994 Details
Description
Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.
A vulnerability allowing sensitive data exposure has been identified in Slah CMS versions through 1.5.0. This issue arises from incorrect access control in the config.php component, where active session credentials are logged in plaintext to a publicly accessible JavaScript file. As a result, unauthenticated attackers can retrieve sensitive information, including session keys, usernames, and passwords, potentially leading to unauthorized account access.
Users are advised to update Slah CMS to the latest patched version. Additionally, the insecure logging mechanism in 'config.php' should be removed, as session credentials must not be written to publicly accessible files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2026CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cve.joaopaulodeoliveira.dev/cve.php/published/CVE-2026-30994 | [email protected] | AdvisoryExploitRemedy |
| https://cve.joaopaulodeoliveira.dev/cve.php/reserved/slah-informatica-sensitive-data-exposure | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Slah | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | New CVE Received | [email protected] |
Volerion