Description
Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.
Remediation
References
Related Vulnerabilities
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4226)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Unspecified Vulnerability (5.7)
Python Integer Overflow or Wraparound Vulnerability (CVE-2016-5636)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-3169)