CVE-2021-25991

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
Configurations

Configuration 1 (hide)

cpe:2.3:a:if-me:ifme:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:55

Type Values Removed Values Added
References () https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923 - Patch, Third Party Advisory () https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923 - Patch, Third Party Advisory
References () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991 - Exploit, Third Party Advisory () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991 - Exploit, Third Party Advisory
CVSS v2 : 4.9
v3 : 7.3
v2 : 4.9
v3 : 5.7

Information

Published : 2021-12-29 09:15

Updated : 2024-11-21 05:55


NVD link : CVE-2021-25991

Mitre link : CVE-2021-25991

CVE.ORG link : CVE-2021-25991


JSON object : View

Products Affected

if-me

  • ifme
CWE
CWE-284

Improper Access Control

NVD-CWE-Other