User Data Manipulation via Path Manipulation Vulnerability in OMERO 5.3.3 or Earlier

User Data Manipulation via Path Manipulation Vulnerability in OMERO 5.3.3 or Earlier

CVE-2017-1000438 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.

Learn more about our User Device Pen Test.