GHSA-wq8p-q8cq-94w5

Suggest an improvement
Source
https://github.com/advisories/GHSA-wq8p-q8cq-94w5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-wq8p-q8cq-94w5/GHSA-wq8p-q8cq-94w5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wq8p-q8cq-94w5
Aliases
  • CVE-2026-1196
Published
2026-01-20T03:30:28Z
Modified
2026-02-05T22:25:41.079391Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Details

A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-05T22:01:08Z",
    "nvd_published_at": "2026-01-20T01:15:56Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / mineadmin/mineadmin

Package

Name
mineadmin/mineadmin
Purl
pkg:composer/mineadmin/mineadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Last affected
2.0.3

Affected versions

v1.*
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13
v2.*
v2.0-stable
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3
2.*
2.0.0-alpha.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-wq8p-q8cq-94w5/GHSA-wq8p-q8cq-94w5.json"