VYPR
High severity8.4NVD Advisory· Published Jan 20, 2025· Updated Apr 15, 2026

CVE-2025-24337

CVE-2025-24337

Description

WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/writefreely/writefreelyGo
<= 0.15.1

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.