What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1.9.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1.9.8.
Explanation of Vulnerability in Simple Terms
Create by Mediavine versions up to 1.9.8 expose sensitive information through improper access controls. An unauthenticated attacker can read data that should be restricted, such as configuration details or user information. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 1.9.8.
What an attacker can do
Read sensitive data that should be restricted, such as configuration or user information.
Potential impact on your site
Sensitive site data may be exposed to anyone on the internet without authentication.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities