GHSA-9hmf-cxg8-mqx6HighCVSS 8.3

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.

🔗 References (7)