Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://github.com/Froxlor/Froxlor/commit/aa881560cc996c38cbf8c20ee62854e27f72c73c | third party advisory patch |