imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.6%