Description
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
Remediation
References
Related Vulnerabilities
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2022-34253)
Oracle JRE CVE-2022-21248 Vulnerability (CVE-2022-21248)
WordPress Plugin Currency Switcher for WooCommerce Security Bypass (2.11.1)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9518)