Vulnerabilities/

Any logged in user could edit any other logged in user.

Severity:
High

Description

Everyone who is running a12n-server.

A new HAL-Form was added to allow editing users. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change.

Recommendation

Update the @curveball/a12n-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@curveball/a12n-server
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing