Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, cate…
High CVSS 7.5
Summary
Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://gist.github.com/itsmohitnarayan/736225bd6cd79031a5dfbf56acdb14ae
- https://gist.github.com/itsmohitnarayan/736225bd6cd79031a5dfbf56acdb14ae
Timeline
- nvd_ingest NVD