Vulnerability Description
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| If-Me | Ifme | >= 5.0.0, <= 7.32 |
Related Weaknesses (CWE)
References
- https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991ExploitThird Party Advisory
- https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991ExploitThird Party Advisory
FAQ
What is CVE-2021-25991?
CVE-2021-25991 is a vulnerability with a CVSS score of 5.7 (MEDIUM). In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete l...
How severe is CVE-2021-25991?
CVE-2021-25991 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25991?
Check the references section above for vendor advisories and patch information. Affected products include: If-Me Ifme.