Skip to content

Portal user could export more datas than his portal scope

High
piRGoif published GHSA-vcv9-xp3j-7jwh Jan 12, 2021

Package

No package listed

Affected versions

< 2.7.2, < 3.0.0

Patched versions

2.7.2, 3.0.0

Description

Impact

When called directly, the ajax endpoint for the "excel export" portal functionality allows to get data without scope filtering.

Patches

Fixed in 2.7.2 and 3.0.0

Credits

Many thanks to SEB / Intrinsec for this report !

References

Combodo ref N°3111

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

High

CVE ID

CVE-2020-4079

Weaknesses

No CWEs