Описание
usememos/memos makes Incorrect Use of Privileged APIs
In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via API DELETE https://demo.usememos.com/api/memo/$idnote. The vulnerability will lose all user notes data throughout the system, causing damage to user data.
Пакеты
Наименование
github.com/usememos/memos
go
Затронутые версииВерсия исправления
<= 0.9.0
0.9.1
Связанные уязвимости
CVSS3: 8.1
nvd
около 3 лет назад
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.