CVE-2012-5892: Havalite CMS
Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.
Affected products
- Havalite CMS: up to and including 1.1.0
Published 2012-11-17. Last modified 2026-06-16.