GHSA-hx6g-q9v2-xh7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-hx6g-q9v2-xh7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-hx6g-q9v2-xh7v/GHSA-hx6g-q9v2-xh7v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hx6g-q9v2-xh7v
Aliases
Published
2021-12-16T15:30:48Z
Modified
2023-11-08T04:06:40.412860Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Information exposure in elgg
Details

elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor. Forms in the view namespace 'forms/admin' were not protected by an AdminGatekeeper in case of AJAX requests to 'ajax/form/admin/'.

Database specific
{
    "nvd_published_at": "2021-12-03T15:15:00Z",
    "github_reviewed_at": "2021-12-06T22:01:08Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-359"
    ]
}
References

Affected packages

Packagist / elgg/elgg

Package

Name
elgg/elgg
Purl
pkg:composer/elgg/elgg

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.23

Affected versions

1.*

1.9.0-rc.1
1.9.0-rc.2
1.9.0-rc.3
1.9.0-rc.4
1.9.0-rc.5
1.9.0-rc.6
1.9.0-rc.7
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.10.0-rc.1
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.12.9
1.12.10
1.12.11
1.12.12
1.12.13
1.12.14
1.12.15
1.12.16
1.12.17
1.12.18

2.*

2.0.0-alpha.1
2.0.0-alpha.2
2.0.0-alpha.3
2.0.0-beta.1
2.0.0-beta.2
2.0.0-beta.3
2.0.0-rc.1
2.0.0-rc.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0-rc.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0-rc.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17

3.*

3.0.0-beta.1
3.0.0-beta.2
3.0.0-beta.3
3.0.0-rc.1
3.0.0-rc.2
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.3.10
3.3.11
3.3.12
3.3.13
3.3.14
3.3.15
3.3.16
3.3.17
3.3.18
3.3.19
3.3.20
3.3.21
3.3.22

Packagist / elgg/elgg

Package

Name
elgg/elgg
Purl
pkg:composer/elgg/elgg

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.5

Affected versions

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4