PT-2026-70796 · Unknown · Ishankportfolio
CVE-2026-48771
·
Published
2026-08-11
·
Updated
2026-08-13
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ishankportfolio versions prior to 1.0.1
Description
Contact form submissions may be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorized users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII), such as names, email addresses, phone numbers, and messages.
Recommendations
Update to version 1.0.1.
Disable public read/write database access.
Rotate exposed API keys.
Restrict database policies to authenticated requests only.
Move sensitive operations to secure backend or serverless functions.
Monitor database activity logs for suspicious access.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ishankportfolio