← Zurück zur CVE-Suche

CVE-2026-79660

Ech0

Beschreibung

Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers can harvest all commenter emails by calling the /api/comments and /api/comments/public endpoints without authentication.

CVSS 5.3EPSS 0.241%Risiko 0.54
Quelle öffnen
Veröffentlicht
2026-08-25 12:16:29
Betroffene Versionen
<4.7.3
Typ
Webanwendung
Zuletzt geändert
2026-08-25 16:17:27
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N