VulnerabilityModified
CVE-2022-25091
Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature.
MEDIUM 5.3EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- infopop/ultimate bulletin board
- Source
- cve@mitre.org
References
- http://www.infopop.com/support/ubbclassic/version5.htmlBroken Link
- https://marc.info/?l=vuln-dev&m=97486849231786&w=2Mailing List
- https://vulners.com/securityvulns/SECURITYVULNS:DOC:954Mailing List
- https://web.archive.org/web/20030207100935/Not Applicable
- https://web.archive.org/web/20030207100935/http://www.infopop.com/support/ubbclassic/version5.htmlRelease Notes
- http://www.infopop.com/support/ubbclassic/version5.htmlBroken Link
- https://marc.info/?l=vuln-dev&m=97486849231786&w=2Mailing List
- https://vulners.com/securityvulns/SECURITYVULNS:DOC:954Mailing List
- https://web.archive.org/web/20030207100935/Not Applicable
- https://web.archive.org/web/20030207100935/http://www.infopop.com/support/ubbclassic/version5.htmlRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.