Vulnerabilities > CVE-2022-41708 - Improper Preservation of Permissions vulnerability in Relatedcode Messenger

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
relatedcode
CWE-281

Summary

Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.

Vulnerable Configurations

Part Description Count
Application
Relatedcode
1

Common Weakness Enumeration (CWE)