Vulnerability Summary
HackerOne disclosed report --> https://hackerone.com/reports/2388183 by hakuna
Admins can decide which groups are allowed to create boards. But a user who is part of an unauthorized group can easily create a new board by cloning an existing one and renaming it.
Users outside of those groups will not be able to create their own boards, but will still be able to work on boards that have been shared with them.
POST /nextcloud/apps/deck/boards/board_number/clone.HackerOne disclosed report --> https://hackerone.com/reports/3543475 by xavlimsg
HackerOne disclosed report --> https://hackerone.com/reports/3020021 by adilnbabras
HackerOne disclosed report --> https://hackerone.com/reports/3325582 by adilnbabras
No comments yet.
Be the first to share your thoughts
Log in to join the discussion.
Sign In