CVE-2026-7071: CodeAstro Online Job Portal user-cvs file information disclosure
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7071?
CVE-2026-7071 is classified as a medium severity vulnerability due to the potential exposure of sensitive user file information.
How do I fix CVE-2026-7071?
To fix CVE-2026-7071, it is recommended to restrict access to the /users/user-cvs/ directory and implement proper authentication measures.
What information is exposed due to CVE-2026-7071?
CVE-2026-7071 leads to file and directory information exposure, which may include sensitive user data.
Which software versions are affected by CVE-2026-7071?
CVE-2026-7071 affects CodeAstro Online Job Portal version 1.0.
Is there a public exploit for CVE-2026-7071?
Currently, no known public exploit exists for CVE-2026-7071, but the vulnerability can still be exploited if not mitigated.