bookstack is vulnerable to Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://huntr.dev/bounties/0bc8b3f7-9057-4eb7-a989-24cd5689f114 | third party advisory exploit |
https://github.com/bookstackapp/bookstack/commit/cb0d674a71449de883713db2fcdccb6e108992ad | third party advisory exploit |