Information Exposure Through an Error Message in Shaarli - #VU151491

 

Information Exposure Through an Error Message in Shaarli - #VU151491

Published: September 21, 2026


Vulnerability identifier: #VU151491
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to generation of an error message containing sensitive information in PageBuilder::initialize() and the index.php fallback error handler when processing array-valued searchtags or searchterm query parameters. A remote attacker can send a request with an array-valued search parameter to disclose sensitive information.

The disclosed information includes the absolute installation path and full application and framework stack trace.


Affected software

Shaarli

Remediation

Install security update from vendor's website.

Shaarli - update to 0.16.6

External References

Related Security Bulletins