Description
Due to a vulnerability in NodeBB, an unauthenticated attacker can access sensitive information from arbitrary JSON files on the server.
Remediation
Upgrade to the latest version of NodeBB
References
Related Vulnerabilities
WordPress Plugin MiniMax-Page Layout Builder Cross-Site Scripting (1.3.4)
WordPress Plugin WP-Matomo (WP-Piwik) Cross-Site Scripting (1.0.4)
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-28334)
WordPress Plugin Photoswipe Masonry Gallery Unspecified Vulnerability (1.2.17)