CVE-2015-2298
12.01.2018, 17:29
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.Enginsight
Vendor | Product | Version |
---|---|---|
etherpad | etherpad | 1.5.0 |
etherpad | etherpad | 1.5.0:d |
etherpad | etherpad | 1.5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References