Vulnerabilities (CVE)

Filtered by vendor Chandler Project Subscribe
Filtered by product Chandler Server
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6383 1 Chandler Project 1 Chandler Server 2024-02-28 5.5 MEDIUM N/A
The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to create arbitrary resources in another user's home collection.