PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403 with ADMIN_ONLY, however, next() would call leading to any updates/changes in the route to process. This issue has been addressed in version 3.2.49. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 01 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-08-14T20:03:10.231Z

Updated: 2024-10-01T19:10:10.299Z

Reserved: 2023-08-08T13:46:25.242Z

Link: CVE-2023-40020

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:54.702Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-14T21:15:13.797

Modified: 2023-08-22T14:36:08.510

Link: CVE-2023-40020

cve-icon Redhat

No data.