See drafts and post articles if the account owner hasn't set password (livedoor CMS plugin)
Critical
L
LY Corporation
Submitted None
Team Summary
Official summary from LY Corporation
For new accounts that haven't set passwords yet, an attacker is able to see drafts or post articles as victims.
Actions:
Reported by
akichia
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic