PT-2020-10266 · Serpico · Serpico

Published

2020-01-15

·

Updated

2021-07-21

·

CVE-2019-19859

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Serpico version 1.3.0
Description An issue was discovered in the Add Collaborator function, which allows unlimited data to be sent via the author parameter, even if the data does not match anything in the database.
Recommendations For Serpico version 1.3.0, consider restricting the use of the author parameter in the Add Collaborator function to prevent unlimited data from being sent. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-19859

Affected Products

Serpico