GHSA-f6hh-58p2-7rx3HighCVSS 8.8
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any...
🔗 CVE IDs covered (1)
📋 Description
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.