Vulnerability Description
ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Modernflow | < 1.3.00.208 |
Related Weaknesses (CWE)
References
- https://4sightwebsite.azurewebsites.net/mf_releaseNotesBroken Link
- https://appsource.microsoft.com/en-us/product/web-apps/acctech-systems-pty-ltd.mProduct
- https://4sightwebsite.azurewebsites.net/mf_releaseNotesBroken Link
- https://appsource.microsoft.com/en-us/product/web-apps/acctech-systems-pty-ltd.mProduct
FAQ
What is CVE-2021-3339?
CVE-2021-3339 is a vulnerability with a CVSS score of 4.3 (MEDIUM). ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
How severe is CVE-2021-3339?
CVE-2021-3339 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3339?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Modernflow.