CVE-2018-18655

Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
References
Link Resource
https://bugs.debian.org/911842 Issue Tracking Mailing List Patch Third Party Advisory
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:prayer_project:prayer:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-10-26 00:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-18655

Mitre link : CVE-2018-18655

CVE.ORG link : CVE-2018-18655


JSON object : View

Products Affected

prayer_project

  • prayer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor