Security Advisory

CVE-2015-2298

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-01-12 17:00:00
Last updated 2024-08-06 05:10:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.