ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
References
Link | Resource |
---|---|
https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl#0x02-modify | Exploit Third Party Advisory |
https://github.com/star7th/showdoc/commit/bcdb5e3519285bdf81e618b3c9b90d22bc49e13c | Patch |
https://github.com/star7th/showdoc/issues/397 | Issue Tracking |
https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl#0x02-modify | Exploit Third Party Advisory |
https://github.com/star7th/showdoc/commit/bcdb5e3519285bdf81e618b3c9b90d22bc49e13c | Patch |
https://github.com/star7th/showdoc/issues/397 | Issue Tracking |
Configurations
History
21 Nov 2024, 03:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl#0x02-modify - Exploit, Third Party Advisory | |
References | () https://github.com/star7th/showdoc/commit/bcdb5e3519285bdf81e618b3c9b90d22bc49e13c - Patch | |
References | () https://github.com/star7th/showdoc/issues/397 - Issue Tracking |
Information
Published : 2018-11-28 08:29
Updated : 2024-11-21 03:58
NVD link : CVE-2018-19620
Mitre link : CVE-2018-19620
CVE.ORG link : CVE-2018-19620
JSON object : View
Products Affected
showdoc
- showdoc
CWE
CWE-425
Direct Request ('Forced Browsing')