CodiMD Unauthorised Image Access
This advisory details a missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to image data uploaded to CodiMD. Due to the insecure random filename generation functionality in the underlying Formidable
library, filenames for uploaded images could be determined and the likelihood of this issue being exploited was increased.