Description
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Redirection Multiple Cross-Site Scripting Vulnerabilities (2.2.11)
Atlassian Confluence Incorrect Authorization Vulnerability (CVE-2023-22518)
MySQL CVE-2014-2442 Vulnerability (CVE-2014-2442)
MySQL CVE-2019-2998 Vulnerability (CVE-2019-2998)
WordPress Plugin Controlled Admin Access Security Bypass (1.4.0)