TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days