Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2018-02-01 17:29
Updated : 2024-11-21 02:26
NVD link : CVE-2015-2203
Mitre link : CVE-2015-2203
CVE.ORG link : CVE-2015-2203
JSON object : View
Products Affected
                evergreen-ils
- evergreen
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
