Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N < 5.15
affected
Description
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.
Problem types
CWE-284: Improper Access Control
CWE-285: Improper Authorization
Product status
References
github.com/...eblate/security/advisories/GHSA-3pmh-24wp-xpf4
github.com/WeblateOrg/weblate/pull/17256
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.