PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403 with ADMIN_ONLY, however, next() would call leading to any updates/changes in the route to process. This issue has been addressed in version 3.2.49. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-08-14T20:03:10.231Z

Updated: 2023-08-14T20:03:10.231Z

Reserved: 2023-08-08T13:46:25.242Z


Link: CVE-2023-40020

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-14T21:15:13.797

Modified: 2023-08-22T14:36:08.510


Link: CVE-2023-40020

JSON object: View

cve-icon Redhat Information

No data.

CWE