QID 996274
Date Published: 2023-12-14
QID 996274: PHP (Composer) Security Update for t3s/content-consent (GHSA-j8cw-ppmv-wj85)
The extension fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference (IDOR) vulnerability with the potential to expose internal content elements.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-j8cw-ppmv-wj85 for updates and patch information.
Vendor References
- GHSA-j8cw-ppmv-wj85 -
github.com/advisories/GHSA-j8cw-ppmv-wj85
CVEs related to QID 996274
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j8cw-ppmv-wj85 | t3s/content-consent |
|