What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
Explanation of Vulnerability in Simple Terms
Newsletters version 4.9.5 and earlier exposes sensitive information through improper access controls. An attacker on the network can read confidential data without authentication or user interaction. The vulnerability affects the Newsletters product and may impact sites using this component for email management.
What an attacker can do
Read sensitive information from the Newsletters component without logging in.
Potential impact on your site
Confidential data stored in Newsletters may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities