VDB
HIGH 8.1

GHSA-rcqf-cpv9-g5jf

Filestash allows attackers to escalate privileges via sending a crafted request

Details

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/mickael-kerjean/filestash
Introduced in: 0

No fixed version published yet for github.com/mickael-kerjean/filestash (go modules). Pin to a known-safe version or switch to an alternative.

References