Replies: 1 comment
-
Hi @bizibabe, Thank you for taking the time to create this discussion. I have updated the severity from |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
I think the severity of the template "misconfiguration/php-fpm-status.yaml" should be increased.
fpm-status allows you to see all web server requests in real time.
For example, a user clicks on a link to reset his password:
pid: 48753
status: inactive
start time: 26/Jul/2023:17:20:38 +0000
start since : 3991
requests : 94
query duration : 136287
request method : GET
request URI: /account/reset_password?token=f2eb7dc04bd461b7a9d
content length: 25
user : -
script : /var/www/html/public/index.php
last cpu request: 36.69
last memory request: 6029312
==> The attacker can then take control of the account
Beta Was this translation helpful? Give feedback.
All reactions