Advisories for Npm/A12n-Server package

2021

Improper Privilege Management

A new HAL-Form was added to allow editing users This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change.