Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.3
CVE-2012-6563
- EPSS 1.23%
- Veröffentlicht 23.05.2013 15:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.
- EPSS 1.34%
- Veröffentlicht 23.09.2011 23:55:03
- Zuletzt bearbeitet 16.06.2026 23:33:49
Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files.