PT-2020-16427 · Marmind · Marmind

Published

2020-11-05

·

Updated

2021-07-21

·

CVE-2020-26506

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Marmind web application version 4.1.141.0
Description The issue allows users with lower privileges to bypass authorization and access files uploaded by administrative users, which are not visible to them in the web GUI.
Recommendations For version 4.1.141.0, update to a newer version that contains a fix for this issue, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26506

Affected Products

Marmind