Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://pleasanter.org/archives/vulnerability-update-202311 | vendor advisory |
https://jvn.jp/en/jp/JVN96209256/ | third party advisory |