PT-2020-16427 · Marmind · Marmind
Published
2020-11-05
·
Updated
2021-07-21
·
CVE-2020-26506
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Marmind web application version 4.1.141.0
Description
The issue allows users with lower privileges to bypass authorization and access files uploaded by administrative users, which are not visible to them in the web GUI.
Recommendations
For version 4.1.141.0, update to a newer version that contains a fix for this issue, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Marmind