Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c5c-5j4h-8q2c

Опубликовано: 16 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

BookStack is vulnerable to Improper Access Control.

BookStack prior to version 21.11.3 is vulnerable to Improper Access Control. A logged-in user with no privileges OR guest user (if public access enabled) can access the /search/users/select AJAX endpoint meant for admins to manage audit logs, to dump all usernames existing in the Bookstack database. This can also be used to harvest email belonging to a user because BookStack also uses the code where(email, like, % . $search . %) to search for users based on email.

Пакеты

Наименование

ssddanbrown/bookstack

composer
Затронутые версииВерсия исправления

< 21.11.3

21.11.3

EPSS

Процентиль: 62%
0.00425
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

bookstack is vulnerable to Improper Access Control

EPSS

Процентиль: 62%
0.00425
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284