PT-2022-13953 · Publify · Publify

Published

2022-05-16

·

Updated

2024-03-06

·

CVE-2022-1553

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions publify versions prior to 9.2.8
Description The issue is related to improper access control in the GitHub repository, allowing attackers to view the contents of password-protected articles on the publify website. This compromises the confidentiality and integrity of users.
Recommendations For versions prior to 9.2.8, update to version 9.2.8 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-PUBLIFY-2022-1553
CVE-2022-1553
GHSA-5JM7-G527-M694

Affected Products

Publify