Security Advisory

CVE-2012-6563

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-05-23 15:00:00
Last updated 2024-08-06 21:36:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.