A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sandstorm | Sandstorm | * | 0.203 (excluding) |