Loading HuntDB...

Users Without Permission Can Download Restricted Files

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A vulnerability was found where it was possible to bypass restrictions imposed on downloading a file if the valid file token was known and by accessing at its URL directly. We thank @imran_nisar for reporting this to our team.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation