{"id":"CVE-2014-6276","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-6276","summary":"schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information…","details":"schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.","published":"2016-04-13T14:59:00.140","modified":"2026-06-17T00:12:49.423","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3502"},{"type":"FIX","url":"https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt"},{"type":"WEB","url":"http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3502"},{"type":"FIX","url":"https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:12:49.423"}}