Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles.
Disclosure of private system profiles: Platform, OS, OS version, Description.
None
https://mantisbt.org/bugs/view.php?id=34640
{
"nvd_published_at": "2024-09-30T15:15:05Z",
"severity": "MODERATE",
"github_reviewed_at": "2024-09-30T17:48:15Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-200"
]
}