The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.172
EPSS Ranking 94.8%