RubySec

Providing security resources for the Ruby community

CVE-2022-1810 (publify_core): Improper Access Control in publify

Improper Access Control in publify

Published: May 24, 2022

SECURITY IDENTIFIERS

GEM

publify_core

SEVERITY

CVSS v3.x: 4.3 (Medium)

PATCHED VERSIONS

>= 9.2.9

DESCRIPTION

A low-privileged user can modify and delete admin articles just by changing the value of the article[id] parameter prior to 9.2.9.

RELATED