Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.55%
Published
Apr 13, 2016
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
Weaknesses (CWE)
Affected Products (3)
References (6)