VulnerabilityModified
CVE-2008-3503
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
MEDIUM 5.0EPSS 1.51%
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- webgui/plain black webgui
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30782Vendor Advisory
- http://www.securityfocus.com/bid/29927
- http://www.vupen.com/english/advisories/2008/1932/references
- http://www.webgui.org/bugs/tracker/security-issue---collaboration-rss/
- http://www.webgui.org/getwebgui/advisories/webgui-7_5_13-beta-released
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43344
- http://secunia.com/advisories/30782Vendor Advisory
- http://www.securityfocus.com/bid/29927
- http://www.vupen.com/english/advisories/2008/1932/references
- http://www.webgui.org/bugs/tracker/security-issue---collaboration-rss/
- http://www.webgui.org/getwebgui/advisories/webgui-7_5_13-beta-released
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43344
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.