What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.
Explanation of Vulnerability in Simple Terms
Flash & HTML5 Video versions up to 2.5.31 expose sensitive information to authenticated users. A logged-in attacker with low privileges can read data they should not have access to. The vulnerability requires network access but no user interaction. Update to a version newer than 2.5.31 to remediate.
What an attacker can do
Read sensitive information accessible only to higher-privilege users or other site users.
Potential impact on your site
Authenticated users with low privileges can view private data, potentially exposing user information or site configuration details.
Conditions required to exploit
Attacker must be logged in with low-level user privileges and have network access.
Key dates
External resources
Related vulnerabilities