Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrg9-7x38-vcrm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

EPSS

Процентиль: 45%
0.00222
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 12 лет назад

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

EPSS

Процентиль: 45%
0.00222
Низкий

Дефекты

CWE-200