CVEs Blog | G5 Cyber Security

CVE-2015-2298 – node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow r

node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2298

Reference (s):

Exit mobile version