ShowDoc 2.4.1 consente agli aggressori remoti alle note Modifica altri utenti navigando con un page_id modificata. |
https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl#0x02-modify https://github.com/star7th/showdoc/commit/bcdb5e3519285bdf81e618b3c9b90d22bc49e13c https://github.com/star7th/showdoc/issues/397 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19620 |
Vulnerabilità: CVE-2018-19620
