ID:6156 - Exploit for Information disclosure in Apache Syncope - CVE-2018-1322
Published: June 17, 2021
Apache Syncope
Link to public exploit:
Vulnerability description
The vulnerability allows a remote authenticated attacker to gain access to potentially sensitive information.
The vulnerability exists due to unspecified error related to processing of the fiql and orderby parameters. A remote authenticated administrator with user search entitlements can gain unauthorized access to sensitive information on the system.