Vulnerabilities > Tianti Project > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-08 CVE-2018-19109 Forced Browsing vulnerability in Tianti Project Tianti 2.3
tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.
network
low complexity
tianti-project CWE-425
8.8