CBS Last.fm Fixes Admin Password Leakage Via Symfony Profiler
CBS Last.fm Fixes Admin Password Leakage Via Symfony Profiler This week, British music streaming service, Last.fm has fixed a credential leakage issue that revealed admin username and password. The leak had occurred due to a misconfigured PHP Symfony app running in “debug” mode and exposing profiler logs. With these credentials, an attacker could have accessed and modified Last.fm user account details. Last.fm web app