PT-2021-17704 · Appspace · Appspace

Published

2021-04-14

·

Updated

2021-04-21

·

CVE-2021-27990

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Appspace version 6.2.4
Description: The issue concerns a broken authentication mechanism. This allows pages such as "/medianet/mail.aspx" to be accessed directly, exposing the framework's layouts, menus, and functionalities.
Recommendations: For Appspace version 6.2.4, consider restricting direct access to sensitive pages like "/medianet/mail.aspx" as a temporary workaround until a patch is available. Additionally, review the authentication mechanism to ensure it properly secures access to the framework's components.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27990

Affected Products

Appspace