Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.
References
| Link | Resource |
|---|---|
| https://gist.github.com/mrtantoine/4331a5f04f8309eb1799b257a7371f34 | Mitigation Third Party Advisory |
| https://magefan.com/magento2-blog-extension | Product |
Configurations
History
No history.
Information
Published : 2026-09-09 19:17
Updated : 2026-09-10 17:48
NVD link : CVE-2026-79323
Mitre link : CVE-2026-79323
CVE.ORG link : CVE-2026-79323
JSON object : View
Products Affected
mageplaza
- magefan_blog
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
