ActiveCollab prior to 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
activecollab activecollab |