Information disclosure in Lussumo Vanilla



| Updated: 2020-07-17
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2011-3613
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
Vanilla
Other software / Other software solutions

Vendor Lussumo

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU30434

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2011-3613

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Vanilla: 2.0.17.1 - 2.0.17.8

CPE2.3 External links

https://packetstormsecurity.com/files/105853/Secunia-Security-Advisory-46387.html
https://www.openwall.com/lists/oss-security/2011/10/10/5


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###