CVE-2020-26506
Summary
| CVE | CVE-2020-26506 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-05 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed files were not visible by the low privileged users in the web GUI. |
Risk And Classification
Problem Types: CWE-670 | CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Marmind Authorization Bypass | MISC | www2.deloitte.com | Exploit, Third Party Advisory |
| MARMIND – Master Your Marketing | MISC | www.marmind.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.