An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.
References
Link | Resource |
---|---|
https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10207/ | Third Party Advisory |
Configurations
Information
Published : 2018-04-25 11:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-10207
Mitre link : CVE-2018-10207
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
vaultize
- enterprise_file_sharing