Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33155
HistoryDec 02, 2021 - 11:14 a.m.

Insecure Access Control

2021-12-0211:14:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
access validation
permission service
unauthorized access
attachment viewing

EPSS

0.001

Percentile

21.4%

ssddanbrown/bookstack does not properly validate user’s access. The permission service allows users to obtain unauthorized access to the API, enabling users to view any attachment without having permission.

EPSS

0.001

Percentile

21.4%