Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.77%
Published
Apr 15, 2014
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.
Weaknesses (CWE)
Affected Products (4)
References (2)