Access Control Vulnerability in Elgg Before Version 1.8.5
CVE-2012-6563

Currently unrated

Key Information:

Vendor

Elgg

Status
Vendor
CVE Published:
23 May 2013

What is CVE-2012-6563?

In Elgg prior to version 1.8.5, a critical access control vulnerability exists in the engine/lib/access.php file. This flaw allows remote attackers to exploit cached access lists during plugin boot, leading to unauthorized access to private entities through unspecified vectors. It emphasizes the necessity for users to upgrade to the latest version to safeguard sensitive information from malicious intrusions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.