An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://web.synametrics.com/SynamanVersionHistory.htm | release notes vendor advisory |
https://github.com/videnlabs/CVE-2022-22828/ | third party advisory exploit |