Vulnerability identifier: #VU31331
Vulnerability risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-200
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Etherpad
Web applications /
CMS
Vendor: The Etherpad Foundation
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Etherpad: 1.6.0 - 1.6.3
External links
http://blog.etherpad.org/2018/04/07/important-release-1-6-4/
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.