Impact
Portal user can see any other contact's picture by changing the picture ID in the URL.
Patches
Fixed in 3.2.1
References
- Combodo N°8150 - [SECU] Portal user can see any other contacts picture
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Credits
Thanks to Florian Audon and Romain Melchiorre for reporting this issue !
Impact
Portal user can see any other contact's picture by changing the picture ID in the URL.
Patches
Fixed in 3.2.1
References
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Credits
Thanks to Florian Audon and Romain Melchiorre for reporting this issue !