High severity7.5NVD Advisory· Published Jan 12, 2018· Updated Jun 17, 2026
CVE-2015-2298
CVE-2015-2298
Description
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2>=1.5.0,<1.5.2+ 1 more
- (no CPE)range: >=1.5.0,<1.5.2
- (no CPE)range: <1.5.2
Patches
Vulnerability mechanics
References
3- github.com/ether/etherpad-lite/commit/a0fb65205c7d7ff95f00eb9fd88e93b300f30c3dnvdPatch
- github.com/ether/etherpad-lite/releases/tag/1.5.2nvdPatchRelease Notes
- www.openwall.com/lists/oss-security/2015/03/15/3nvdIssue TrackingMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.