📄 Docmost 0.70.x Authorization Bypass_PACKETSTORM:224388
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace. Versions 0.3.0 through 0.70.x are affected...