Jerome Bruandet, from NinTechNet, discovered a broken access control issue in the plugin, which could lead to unauthenticated arbitrary file and RCE.
Jerome Bruandet (NinTechNet)
No
2020-09-25 (about 2 years ago)
2020-09-25 (about 2 years ago)
2020-09-26 (about 2 years ago)