HIGH🇬🇧 English

CVE-2022-1252

CVSS 8.2v3.1pub. 2022-04-11upd. 2026-02-24

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when the 'Let others see my information.' box is ticked off. Or to send emails to any email address, with full control of its contents

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  • Sir Gnuboard

    APP
    Sir
    ≤ 5.5.5
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-18662CRITICAL9.8PL ✓ten sam produkt

SQL Injection w gnuboard5 przez parametr table_prefix w install_db.php

CVE-2005-0269CRITICAL9.8PL ✓ten sam produkt

GNUBoard: bypass weryfikacji rozszerzenia pliku przez wielkie litery

CVE-2024-41475HIGH8.8ten sam produkt

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

CVE-2022-44216HIGH7.5ten sam produkt

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users w...

CVE-2011-4066HIGH7.5ten sam produkt

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute a...