What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts to subscribers: from n/a through 6.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts to subscribers: from n/a through 6.2.
Explanation of Vulnerability in Simple Terms
Email posts to subscribers version 6.2 and earlier exposes sensitive information to unauthenticated attackers over the network. The vulnerability allows an attacker to read data that should be restricted, such as email addresses or post content intended only for subscribers. No user interaction or special privileges are required to exploit this flaw. Site administrators should update to a version newer than 6.2 as soon as a patch becomes available.
What an attacker can do
Read sensitive information like email addresses or subscriber data without authentication.
Potential impact on your site
Subscriber email addresses and potentially private post content may be exposed to anyone on the internet.
Conditions required to exploit
Network access only; no authentication, special privileges, or user interaction required.
Key dates
External resources
Related vulnerabilities