PT-2022-13700 · Unknown · Be Popia Compliant

Chris Meistre

·

Published

2022-04-19

·

Updated

2026-04-08

·

CVE-2022-1186

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Be POPIA Compliant versions up to and including 1.1.5
Description The issue exposes sensitive information, including site visitors' emails and usernames, to unauthenticated users through an API route.
Recommendations For versions up to and including 1.1.5, update to a version higher than 1.1.5 to resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-1186

Affected Products

Be Popia Compliant