CVE-2019-12782
09.07.2019, 16:15
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.Enginsight
Vendor | Product | Version |
---|---|---|
thoughtspot | thoughtspot | 4.4.1 ≤ 𝑥 ≤ 5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References