bookstack is vulnerable to Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://huntr.dev/bounties/c6dfa80d-43e6-4b49-95af-cc031bb66b1d | third party advisory exploit |
https://github.com/bookstackapp/bookstack/commit/b4fa82e3298a15443ca40bff205b7a16a1031d92 | third party advisory patch |