Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://huntr.dev/bounties/2c684f99-d181-4106-8ee2-64a76ae6a348 | patch third party advisory exploit |
https://github.com/answerdev/answer/commit/964195fd859ee5d7171fac847374dfa31893e793 | patch |