Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26596
HistorySep 03, 2020 - 5:00 a.m.

Information Disclosure

2020-09-0305:00:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.001 Low

EPSS

Percentile

22.7%

derhansen/sf_event_mgt is vulnerable to information disclosure. Missing access checks in the backend module allows an authenticated user to export restricted participant data for events or send emails to event participants for events which the user does not have access to.

0.001 Low

EPSS

Percentile

22.7%

Related for VERACODE:26596