Snorby contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when an unspecified error occurs in the in_xml() method in app/models/event.rb. This may allow a remote attacker to gain access to XML user information.