CVE-2021-36388
14.10.2021, 19:15
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".Enginsight
Vendor | Product | Version |
---|---|---|
yellowfinbi | yellowfin | 𝑥 < 9.6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References