Loading HuntDB...

Viewer is able to leak the previous versions of the file

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A vulnerability was found where a low level user with only view permissions to a specific file version was able to access previous versions of the file without proper access permissions. We thank @snapsec for reporting this to our team.

Reported by imran0x01

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic