GHSA-x6x4-g3x8-4p64HighCVSS 7.5

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.

🔗 References (3)