VWE-2010-0122-2 Printable Version
This page is a chapter in Info Known Vulnerabilities
This page has been seen 8,819 times.
-
-
Created by on
-
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2010-0122-2 Related Report #2089 Severity MEDIUM Exploit Difficulty EASY Platform Affects all platforms supported by the vulnerable versions. Description Permissions escalation. Users can see the content of moderated templates if those templates are included by content they can view.
Discovered November 16, 2010 Resolved November 22, 2010 Patches Available 3.0.6
Notes
This permissions escalation was incorrectly handled as a standard bug at the time it was patched. As a result, although the problematic code existed in the 2.x series, it was never patched in that series. For the same reason, patches for earlier versions in the 3.x series continued to have this issue, even though they were released after this issue was patched.