CVE-2021-4119
critical · 9.8bookstack is vulnerable to Improper Access Control
9.8
CVSS
26.9%
EPSS (exploit prob.)
98th
EPSS percentile
2021-12-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-284
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| bookstackapp | bookstack | <= 21.11.2 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/bookstackapp/bookstack/commit/e765e618547c92f4e0b46caca6fb91f0174efd99
- https://huntr.dev/bounties/135f2d7d-ab0b-4351-99b9-889efac46fca
- https://github.com/bookstackapp/bookstack/commit/e765e618547c92f4e0b46caca6fb91f0174efd99
- https://huntr.dev/bounties/135f2d7d-ab0b-4351-99b9-889efac46fca
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-4119