CVE-2021-3339

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
19/02/2021
Last modified:
25/02/2021

Description

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:modernflow:*:*:*:*:*:*:*:* 1.3.00.208 (excluding)