Lucene search

K
osvGoogleOSV:CVE-2020-12687
HistoryMay 07, 2020 - 4:15 p.m.

CVE-2020-12687

2020-05-0716:15:11
Google
osv.dev
10

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

27.0%

An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachments of all users (including administrators) from the database.

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

27.0%

Related for OSV:CVE-2020-12687