The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to create arbitrary resources in another users home collection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chandler_server | Chandler_project | * | 0.10 (including) |