VDB
Sign up
MEDIUM5.3

GHSA-9c5c-5j4h-8q2c

BookStack is vulnerable to Improper Access Control.

Quick fix

GHSA-9c5c-5j4h-8q2c — ssddanbrown/bookstack: upgrade to the fixed version with the command below.

composer require ssddanbrown/bookstack:^21.11.3

Details

BookStack prior to version 21.11.3 is vulnerable to Improper Access Control. A logged-in user with no privileges OR guest user (if public access enabled) can access the /search/users/select AJAX endpoint meant for admins to manage audit logs, to dump all usernames existing in the Bookstack database. This can also be used to harvest email belonging to a user because BookStack also uses the code where(`email`, `like`, `%` . $search . `%`) to search for users based on email.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ssddanbrown/bookstack
Introduced in: 0Fixed in: 21.11.3
Fixcomposer require ssddanbrown/bookstack:^21.11.3

References