PT-2021-21267 · Yellowfin · Yellowfin

Cyberaz0R

+1

·

Published

2021-10-14

·

Updated

2024-05-14

·

CVE-2021-36389

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yellowfin versions prior to 9.6.1
Description The issue allows enumeration and download of uploaded images through an Insecure Direct Object Reference vulnerability. This can be exploited by sending a specially crafted HTTP GET request to the "MIImage.i4" page.
Recommendations For versions prior to 9.6.1, update to version 9.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "MIImage.i4" page to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2021-36389

Affected Products

Yellowfin