CVE-2021-27990
HIGHAppspace 6.2.4 - Improper Authentication via Direct Page Access
Title source: llmDescription
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
http://appspace.com
Third Party Advisory x_refsource_misc
https://github.com/syedsohaibkarim/PoC-BrokenAuth-AppSpace6.2.4
Scores
CVSS v3
7.5
EPSS
0.0147
EPSS Percentile
70.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-287
Status
published
Products (1)
appspace/appspace
6.2.4
Published
Apr 14, 2021
Tracked Since
Feb 18, 2026