Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 84.7%