Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99269
HistoryOct 15, 2021 - 12:00 a.m.

Yellowfin insecure direct object reference vulnerability

2021-10-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.006 Low

EPSS

Percentile

78.1%

An insecure direct object reference vulnerability exists in versions of Yellowfin prior to 9.6.1, a business intelligence automated analytics, cross-vendor narrative and collaboration software suite. An attacker could exploit the vulnerability by sending a specially crafted HTTP GET request to the page “MIImage.i4” to enumerate and download an uploaded image.

CPENameOperatorVersion
yellowfin yellowfinlt9.6.1

0.006 Low

EPSS

Percentile

78.1%

Related for CNVD-2021-99269