CVE-2024-37930

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theme-sphere:smartmag:*:*:*:*:*:wordpress:*:*

History

12 Sep 2024, 21:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:theme-sphere:smartmag:*:*:*:*:*:wordpress:*:*
Summary
  • (es) Exposición de información confidencial a un actor no autorizado, vulnerabilidad de autorización faltante en ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs. Este problema afecta a SmartMag: desde n/a hasta 9.3.0.
First Time Theme-sphere
Theme-sphere smartmag
References () https://patchstack.com/database/vulnerability/smartmag-responsive-retina-wordpress-magazine/wordpress-smartmag-theme-9-3-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/smartmag-responsive-retina-wordpress-magazine/wordpress-smartmag-theme-9-3-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve - Third Party Advisory

12 Aug 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 23:15

Updated : 2024-09-12 21:24


NVD link : CVE-2024-37930

Mitre link : CVE-2024-37930

CVE.ORG link : CVE-2024-37930


JSON object : View

Products Affected

theme-sphere

  • smartmag
CWE
CWE-862

Missing Authorization

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor