Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jvx-vcjh-9488

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

EPSS

Процентиль: 15%
0.00242
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
15 дней назад

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

EPSS

Процентиль: 15%
0.00242
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-639