PT-2024-26079 · Unknown · Group Sharing
Published
2024-09-03
·
Updated
2024-09-05
·
CVE-2024-34659
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GroupSharing versions prior to 13.6.13.3
Description
The issue allows remote attackers to force victims to join a group, resulting in exposure of sensitive information. This can be achieved by exploiting the vulnerability in GroupSharing.
Recommendations
For versions prior to 13.6.13.3, upgrade to version 13.6.13.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information within GroupSharing until the upgrade is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Group Sharing