Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Eloan | Eloan_project | 3.0 (including) | 2018-09-20 (including) |