elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor. Forms in the view namespace 'forms/admin' were not protected by an AdminGatekeeper in case of AJAX requests to 'ajax/form/admin/'.
{ "nvd_published_at": "2021-12-03T15:15:00Z", "github_reviewed_at": "2021-12-06T22:01:08Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-359" ] }