MEDIUM
ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL
Published Jan 7, 2011
6.0
MEDIUMCVSS 2.0
EPSS 1.52%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.