CVE-2021-3339

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:modernflow:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:21

Type Values Removed Values Added
References () https://4sightwebsite.azurewebsites.net/mf_releaseNotes - Broken Link () https://4sightwebsite.azurewebsites.net/mf_releaseNotes - Broken Link
References () https://appsource.microsoft.com/en-us/product/web-apps/acctech-systems-pty-ltd.modernflow-saas?tab=overview - Product () https://appsource.microsoft.com/en-us/product/web-apps/acctech-systems-pty-ltd.modernflow-saas?tab=overview - Product

Information

Published : 2021-02-19 08:15

Updated : 2024-11-21 06:21


NVD link : CVE-2021-3339

Mitre link : CVE-2021-3339

CVE.ORG link : CVE-2021-3339


JSON object : View

Products Affected

microsoft

  • modernflow
CWE
CWE-287

Improper Authentication