CVE-2018-19133: Infoleak
Published Nov 9, 2018
·Updated
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
Affected Software
2 affected components
composer/flarum/framework<=0.1.0-beta.7.1
Flarum Flarum=0.1.0-beta.7.1
Remediation
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
May 14, 2022
Advisory Published
01:44 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-19133?
CVE-2018-19133 is classified as a critical vulnerability due to the potential leak of user email addresses.
2
How do I fix CVE-2018-19133?
To fix CVE-2018-19133, upgrade Flarum to a version that addresses this vulnerability.
3
What versions are affected by CVE-2018-19133?
CVE-2018-19133 specifically affects Flarum Core version 0.1.0-beta.7.1.
4
What kind of data is exposed by CVE-2018-19133?
CVE-2018-19133 can result in the unintended exposure of all registered users' email addresses.
5
Is user data secure on Flarum if CVE-2018-19133 is unpatched?
User data is not secure on Flarum if CVE-2018-19133 remains unpatched, as email addresses can be accessed by unauthorized individuals.