Description
Due to a vulnerability in NodeBB, an unauthenticated attacker can access sensitive information from arbitrary JSON files on the server.
Remediation
Upgrade to the latest version of NodeBB
References
Related Vulnerabilities
Atlassian Jira Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6619)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (3.9.7)
Moodle Configuration Vulnerability (CVE-2012-0797)
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.4)