CVE-2022-25091

Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:infopop:ultimate_bulletin_board:*:*:*:*:*:*:*:*

History

03 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-863

21 Nov 2024, 06:51

Type Values Removed Values Added
References () http://www.infopop.com/support/ubbclassic/version5.html - Broken Link () http://www.infopop.com/support/ubbclassic/version5.html - Broken Link
References () https://marc.info/?l=vuln-dev&m=97486849231786&w=2 - Mailing List () https://marc.info/?l=vuln-dev&m=97486849231786&w=2 - Mailing List
References () https://vulners.com/securityvulns/SECURITYVULNS:DOC:954 - Mailing List () https://vulners.com/securityvulns/SECURITYVULNS:DOC:954 - Mailing List
References () https://web.archive.org/web/20030207100935/ - Not Applicable () https://web.archive.org/web/20030207100935/ - Not Applicable
References () https://web.archive.org/web/20030207100935/http://www.infopop.com/support/ubbclassic/version5.html - Release Notes () https://web.archive.org/web/20030207100935/http://www.infopop.com/support/ubbclassic/version5.html - Release Notes

Information

Published : 2023-04-27 21:15

Updated : 2025-02-03 18:15


NVD link : CVE-2022-25091

Mitre link : CVE-2022-25091

CVE.ORG link : CVE-2022-25091


JSON object : View

Products Affected

infopop

  • ultimate_bulletin_board
CWE
NVD-CWE-noinfo CWE-863

Incorrect Authorization