The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which could allow remote attackers to upload files and possibly join a user community that was intended to be closed.
| Software | From | Fixed in |
|---|---|---|
| fraunhofer_fit / bscw | 3.4 | 3.4.x |
| fraunhofer_fit / bscw | 4.0.6 | 4.0.6.x |
| fraunhofer_fit / bscw | 4.0 | 4.0.x |