PT-2020-19988 · Nextcloud · Groupfolders
Francesco Moro
+1
·
Published
2020-05-12
·
Updated
2022-05-24
·
CVE-2020-8153
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Groupfolders app version 4.0.3
Description
The issue is related to improper access control, allowing unauthorized deletion of hidden directories. This occurs when renaming an accessible item to the same name as a hidden directory in the Groupfolders app.
Recommendations
For version 4.0.3, update to a newer version that addresses the improper access control issue to prevent unauthorized deletion of hidden directories.
Exploit
Fix
Improper Access Control
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Groupfolders