Description
Due to a vulnerability in NodeBB, an unauthenticated attacker can access sensitive information from arbitrary JSON files on the server.
Remediation
Upgrade to the latest version of NodeBB
References
Related Vulnerabilities
Chamilo Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-27426)
WordPress Plugin Disqus Comment System Cross-Site Scripting (2.68)
WordPress Plugin School Management System-WPSchoolPress Multiple Vulnerabilities (2.1.9)
WordPress Plugin Post Recommendations for WordPress 'api.php' Remote File Include (1.1.2)
WordPress Plugin Contact Form 7 Datepicker Cross-Site Scripting (2.6.0)