Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/5f3bc4b6-1d53-46b7-a23d-70f5faaf0c76 | exploit third party advisory patch |
https://github.com/jgraph/drawio/commit/59887e45b36f06c8dd4919a32bacd994d9f084da | third party advisory patch |