VWE-2010-0122-2 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2010-0122-2
This page is a chapter in Info Known Vulnerabilities

This page has been seen 8,819 times.

    • Created by on
Common NameNone
VWE-IDVWE-2010-0122-2
Related Report#2089
SeverityMEDIUM
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation. Users can see the content of moderated templates if those templates are included by content they can view.
DiscoveredNovember 16, 2010
ResolvedNovember 22, 2010
Patches Available3.0.6
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.

Notes

This permissions escalation was incorrectly handled as a standard bug at the time it was patched. As a result, although the problematic code existed in the 2.x series, it was never patched in that series. For the same reason, patches for earlier versions in the 3.x series continued to have this issue, even though they were released after this issue was patched.