HIGH🇵🇱 Wersja polska

CVE-2022-1252

CVSS 8.2v3.1pub. 2022-04-11upd. 2026-02-24

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when the 'Let others see my information.' box is ticked off. Or to send emails to any email address, with full control of its contents

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  • Sir Gnuboard

    APP
    Sir
    ≤ 5.5.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-18662CRITICAL9.8PL ✓same product

SQL Injection w gnuboard5 przez parametr table_prefix w install_db.php

CVE-2005-0269CRITICAL9.8PL ✓same product

GNUBoard: bypass weryfikacji rozszerzenia pliku przez wielkie litery

CVE-2024-41475HIGH8.8same product

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

CVE-2022-44216HIGH7.5same product

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users w...

CVE-2011-4066HIGH7.5same product

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute a...