{"id":"CVE-2018-19609","aliases":["GHSA-6xx7-cphv-pxgr"],"url":"https://o3.security/vulnerability/CVE-2018-19609","summary":"Showdoc Forced Browsing","details":"ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.","published":"2018-11-27T16:29:01.363Z","modified":"2026-08-07T15:11:24.510795Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"showdoc/showdoc","fixedVersion":null}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:11:24.510795Z"}}