CVE-2018-18655

Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
References
Link Resource
https://bugs.debian.org/911842 Issue Tracking Mailing List Patch Third Party Advisory
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 Not Applicable
https://bugs.debian.org/911842 Issue Tracking Mailing List Patch Third Party Advisory
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:prayer_project:prayer:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:56

Type Values Removed Values Added
References () https://bugs.debian.org/911842 - Issue Tracking, Mailing List, Patch, Third Party Advisory () https://bugs.debian.org/911842 - Issue Tracking, Mailing List, Patch, Third Party Advisory
References () https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 - Not Applicable () https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 - Not Applicable

Information

Published : 2018-10-26 00:29

Updated : 2024-11-21 03:56


NVD link : CVE-2018-18655

Mitre link : CVE-2018-18655

CVE.ORG link : CVE-2018-18655


JSON object : View

Products Affected

prayer_project

  • prayer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor