#VU22631 Information disclosure in IgniteUp - Coming Soon and Maintenance Mode - CVE-2019-17237
Published: November 11, 2019
IgniteUp - Coming Soon and Maintenance Mode
Ceylon Systems
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the "createCsvFile" and "createBccFile" functions do not check the user capabilities and lack a security nonce. A remote attacker can gain unauthorized access to sensitive information on the system, such as download all email addresses.