Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.
History

Thu, 12 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Theme-sphere
Theme-sphere smartmag
CPEs cpe:2.3:a:theme-sphere:smartmag:*:*:*:*:*:wordpress:*:*
Vendors & Products Theme-sphere
Theme-sphere smartmag

Tue, 13 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Themesphere
Themesphere smartmag
CPEs cpe:2.3:a:themesphere:smartmag:*:*:*:*:*:*:*:*
Vendors & Products Themesphere
Themesphere smartmag
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 Aug 2024 23:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.
Title WordPress SmartMag theme <= 9.3.0 - Sensitive Data Exposure via Log File vulnerability
Weaknesses CWE-200
CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-08-12T23:00:54.742Z

Updated: 2024-08-13T14:01:48.112Z

Reserved: 2024-06-10T21:14:12.905Z

Link: CVE-2024-37930

cve-icon Vulnrichment

Updated: 2024-08-13T14:01:36.626Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T23:15:15.940

Modified: 2024-09-12T21:24:59.393

Link: CVE-2024-37930

cve-icon Redhat

No data.