Security Advisory

CVE-2018-25007

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-04-23 16:05:40
Last updated 2024-09-16 18:18:49
Assigner Vaadin
CVSS score 2.6
State PUBLISHED

Description

Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.