BookStack is an open source set of BookStackApp (Bookstackapp) team’s platform for building wiki documents using PHP and Laravel. bookstackapp suffers from an access control error vulnerability that stems from the fact that users with API access can view any attachments to which they do not have read access. An attacker could exploit the vulnerability to obtain sensitive information.