Description
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
References (2)
Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/5f3bc4b6-1d53-46b7-a23d-70f5faaf0c76
Patch, Third Party Advisory x_refsource_misc
https://github.com/jgraph/drawio/commit/59887e45b36f06c8dd4919a32bacd994d9f084da
Scores
CVSS v3
7.5
EPSS
0.0098
EPSS Percentile
57.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-284
Status
published
Products (1)
diagrams/drawio
< 20.2.8
Published
Sep 02, 2022
Tracked Since
Feb 18, 2026