xuechengen/xinhu-oa

xuechengen/xinhu-oa

Releases0
xinhu oa Information leakage

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.