icon

We found results for “

WS-2021-0109

Date: May 20, 2021

Overview

In `dapps`, version 1.3.0 is vulnerable to `Information Exposure` vulnerability, since the application is routing some specific requests directly without checking whether the application is logged in, and later it redirects to the Login page. Due to this flaw, some information can be viewed without login.

Details

The `dapps` module can be abused by `Information Exposure` vulnerability, since the application is routing some specific requests directly without checking whether the application is logged in, and later it redirects to the Login page. Due to this flaw, some information can be viewed without login.

Affected Environments

1.3.0

Prevention

No fix

Language: JS

Good to know:

icon

Information Leak / Disclosure

CWE-200
icon

Upgrade Version

No fix version available

Base Score:
Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope (S): Unchanged
Confidentiality (C): None
Integrity (I): None
Availability (A): High