Описание
Information exposure in elgg
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor. Forms in the view namespace 'forms/admin' were not protected by an AdminGatekeeper in case of AJAX requests to 'ajax/form/admin/'.
Пакеты
Наименование
elgg/elgg
composer
Затронутые версииВерсия исправления
< 3.3.23
3.3.23
Наименование
elgg/elgg
composer
Затронутые версииВерсия исправления
>= 4.0.0, < 4.0.5
4.0.5
Связанные уязвимости
CVSS3: 7.5
nvd
около 4 лет назад
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
CVSS3: 7.5
debian
около 4 лет назад
elgg is vulnerable to Exposure of Private Personal Information to an U ...