Vulnerabilities/

Firepad allows insecure document access

Severity:
Low

Description

Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content that has previously been pasted into the document. NOTE: in several similar products, this is the intentional behavior for anyone who knows the full document ID and corresponding URL.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
firepad
Anything's wrong? Let us know Last updated on December 05, 2024

This issue is available in SmartScanner Professional

See Pricing