First published: Fri Feb 07 2025(Updated: )
### Impact - Information that is restricted from viewing in the search results of site searches (※) can still be viewed via the main text (a feature added in v1.8.0). - Impact by version - v1.8.0 ~ v1.8.3: It will be displayed in the text. - v1.8.0 and earlier: It will not be displayed in the body of the text, but the title (frame name) will be displayed with a link. - Target viewing restriction function - Frame publishing function (private, limited publishing) - IP Restriction Page - Password setting page ### Patches (fixed version) - Apply v1.8.4. ### Workarounds - Remove the site search (e.g. hide frames).。 ### References none
Affected Software | Affected Version | How to fix |
---|---|---|
composer/opensource-workshop/connect-cms | <=1.8.3 | 1.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Sensitive information that should be restricted can be displayed in the main text of the site search results between versions 1.8.0 and 1.8.3.
Versions 1.8.0 to 1.8.3 of the open-source workshop connect-cms are affected by this vulnerability.
Upgrade to version 1.8.4 of the connect-cms package to resolve this vulnerability.
The open-source workshop connect-cms versions 1.8.0 through 1.8.3 are vulnerable.
No specific workarounds are provided, the recommended action is to upgrade to a non-vulnerable version.