CVE Vulnerabilities

CVE-2018-19620

Direct Request ('Forced Browsing')

Published: Nov 28, 2018 | Modified: Oct 03, 2019
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

ShowDoc 2.4.1 allows remote attackers to edit other users notes by navigating with a modified page_id.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Showdoc Showdoc 2.4.1 (including) 2.4.1 (including)

Potential Mitigations

References