CyberRota Analysis
AI-GeneratedAn unauthenticated information disclosure vulnerability in Feedbin allows attackers to bypass authorization and access private article content via the entries text API endpoint. By sequentially querying entry IDs, attackers can extract sensitive information, including private newsletters and personal page-saves, posing a significant risk to user privacy. Organizations using Feedbin should prioritize remediation to protect user data from unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-saves, and articles from any user's private subscriptions.