CVE-2024-29316

MEDIUM6.3EPSS 0.09%

Incorrect Access Control in NodeBB

Published: 3/29/2024Modified: 11/18/2024
Also known as:GHSA-qc99-r4wh-c8h6

Description

In NodeBB prior to 3.6.7 an attacker was able to access the restricted tabs for the Admin group which are only allowed the the administrators.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References (4)