Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cv3-mmc6-j68f

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6

Описание

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

EPSS

Процентиль: 13%
0.00222
Низкий

7.6 High

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
15 дней назад

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

EPSS

Процентиль: 13%
0.00222
Низкий

7.6 High

CVSS4

Дефекты

CWE-862