First published: Wed Apr 14 2021(Updated: )
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Appspace Appspace | =6.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27990 is a vulnerability in Appspace version 6.2.4 that allows unauthorized access to certain pages and exposes the framework with layouts, menus, and functionalities.
CVE-2021-27990 has a severity rating of 7.5, which is considered high.
Appspace version 6.2.4 is affected by CVE-2021-27990.
To fix CVE-2021-27990, update to a version of Appspace that is not affected by this vulnerability.
More information about CVE-2021-27990 can be found on the official Appspace website and the GitHub repository linked in the references section.