Описание
Etherpad Lite Access Restriction Bypass
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
Пакеты
Наименование
ep_etherpad-lite
npm
Затронутые версииВерсия исправления
< 1.6.3
1.6.3
Связанные уязвимости
CVSS3: 9.8
nvd
почти 8 лет назад
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
CVSS3: 9.8
debian
почти 8 лет назад
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandl ...