CVE-2021-25991

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
Configurations

Configuration 1 (hide)

cpe:2.3:a:if-me:ifme:*:*:*:*:*:*:*:*

History

10 Jan 2022, 16:29

Type Values Removed Values Added
CPE cpe:2.3:a:if-me:ifme:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References (MISC) https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991 - (MISC) https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991 - Exploit, Third Party Advisory
References (CONFIRM) https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923 - (CONFIRM) https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.9
v3 : 7.3

29 Dec 2021, 19:15

Type Values Removed Values Added
Summary In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to self-ban themself leading to their deactivation from Ifme account and complete loss of admin access in Ifme. In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

29 Dec 2021, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-29 09:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-25991

Mitre link : CVE-2021-25991

CVE.ORG link : CVE-2021-25991


JSON object : View

Products Affected

if-me

  • ifme
CWE
NVD-CWE-Other CWE-284

Improper Access Control