Описание
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0.0 (включая) до 7.32 (включая)
cpe:2.3:a:if-me:ifme:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00192
Низкий
5.7 Medium
CVSS3
7.3 High
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-284
NVD-CWE-Other
Связанные уязвимости
github
около 4 лет назад
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
EPSS
Процентиль: 41%
0.00192
Низкий
5.7 Medium
CVSS3
7.3 High
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-284
NVD-CWE-Other