An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104273 | vdb entry third party advisory |
https://developer.joomla.org/security-centre/731-20180503-core-information-disclosure-about-unpublished-tags.html | vendor advisory |
http://www.securitytracker.com/id/1040966 | vdb entry third party advisory |