PT-2023-24198 · Xibo · Xibo

·

CVE-2023-33181

·

Publicado

2023-05-30

·

Atualizado

2023-06-06

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions 3.0.0 through 3.3.4
Description Xibo is a content management system (CMS) that has an issue where some API routes print a stack trace when called with missing or invalid parameters, revealing sensitive information about the server's path locations.
Recommendations For versions 3.0.0 through 3.3.4, upgrade to version 3.3.5 to fix the issue. As a temporary workaround, consider restricting access to the affected API routes until the issue is resolved by upgrading to version 3.3.5.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33181
GHSA-C9CX-GHWR-X58M

Produtos afetados

Xibo