← Back to CVE List

CVE-2021-36388

Published: 2021-10-14T19:15Z
Last Modified: 2024-11-21T06:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4". > MITRE Terms of Use apply – see LICENSE‑MITRE.txt