CVE-2025-24337

Name
CVE-2025-24337
Description
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/writefreely/writefreely/releases/tag/v0.15.1
cve@mitre.org https://raphus.social/@TV4Fun/113846757112643161
cve@mitre.org https://www.openwall.com/lists/oss-security/2025/01/18/1

Match rules

CPE URI Source package Min version Max version
writefreely >= 0 <= 0.15.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
writefreely edge-community 0.15.1-r11 None possibly vulnerable
writefreely edge-community 0.15.1-r10 None possibly vulnerable
writefreely edge-community 0.15.1-r9 None possibly vulnerable
writefreely edge-community 0.15.1-r8 None possibly vulnerable
writefreely edge-community 0.15.1-r7 None possibly vulnerable
writefreely edge-community 0.15.1-r6 None possibly vulnerable
writefreely edge-community 0.15.1-r5 None possibly vulnerable
writefreely edge-community 0.15.1-r4 None possibly vulnerable
writefreely edge-community 0.15.1-r3 None possibly vulnerable
writefreely edge-community 0.15.1-r2 None possibly vulnerable
writefreely edge-community 0.15.1-r1 None possibly vulnerable
writefreely edge-community 0.15.1-r0 None possibly vulnerable
writefreely 3.23-community 0.15.1-r11 None possibly vulnerable
writefreely 3.23-community 0.15.1-r10 None possibly vulnerable
writefreely 3.22-community 0.15.1-r9 None possibly vulnerable
writefreely 3.22-community 0.15.1-r8 None possibly vulnerable
writefreely 3.22-community 0.15.1-r7 None possibly vulnerable
writefreely 3.22-community 0.15.1-r6 None possibly vulnerable
writefreely 3.22-community 0.15.1-r5 None possibly vulnerable