We found results for “”
WS-2022-0458
Good to know:
Date: October 9, 2022
Liberapay was discovered to contain Email Address Exposure via Gratipay Migration Tool. Through the /migrate route, an attacker can input the username of any user on the site and retrieve their primary email address without any authorization required. The issue is resolved in 675.
Language: Python
Severity Score
Related Resources (2)
Severity Score
Weakness Type (CWE)
Information Leak / Disclosure
CWE-200Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |