CVE-2019-15302

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
5.5
MEDIUM
Affected
1
PROJECT

Description

The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.

Collaborative office suite, end-to-end encrypted and open-source.
GitHubGitHub
7.72K