PT-2024-28437 · Toy-Blog · Toy-Blog

Kisaragieffective

·

Published

2024-07-01

·

Updated

2024-07-02

·

CVE-2024-39313

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions toy-blog versions 0.5.4 through 0.6.0
Description The issue allows articles with private visibility to be read without proper credentials. This can lead to unauthorized access to sensitive information. Users are advised to upgrade to a newer version to receive the necessary patch.
Recommendations For toy-blog versions 0.5.4 through 0.6.0, upgrade to version 0.6.1 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-39313
GHSA-RF2Q-5Q4Q-5FWR

Affected Products

Toy-Blog