CVE-2023-40020
CVSS 3.1 Score 8.3 of 10 (high)
Details
Published Aug 14, 2023
Updated: Aug 22, 2023
CWE ID 287
Summary
CVE-2023-40020 is a vulnerability affecting the PrivateUploader image hosting server, written in Vue and TypeScript. In versions prior to 3.2.49, the `app/routes/v3/admin.controller.ts` file failed to properly verify administrator or moderator privileges. Consequently, unauthorized users could continue processing requests, resulting in potential update or change actions. The issue is resolved in version 3.2.49, and users are strongly urged to upgrade. There are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.