Security Advisory
CVE-2010-0215
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.