An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.
References
Link | Resource |
---|---|
https://github.com/rawchen/blog-ssm/issues/5 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2023-01-26 13:16
Updated : 2023-02-01 12:43
NVD link : CVE-2022-40036
Mitre link : CVE-2022-40036
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
blog-ssm_project
- blog-ssm