PT-2024-28437 · Toy-Blog · Toy-Blog

·

CVE-2024-39313

·

Published

2024-07-01

·

Updated

2024-07-02

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions toy-blog versions 0.5.4 through 0.6.0
Description The issue allows articles with private visibility to be read without proper credentials. This can lead to unauthorized access to sensitive information. Users are advised to upgrade to a newer version to receive the necessary patch.
Recommendations For toy-blog versions 0.5.4 through 0.6.0, upgrade to version 0.6.1 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39313
GHSA-RF2Q-5Q4Q-5FWR

Affected Products

Toy-Blog