Vulnerability Description
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Askbot | Askbot | <= 0.12.2 |
Related Weaknesses (CWE)
References
- https://askbot.com/Product
- https://fluidattacks.com/advisories/ghostExploitThird Party Advisory
- https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cPatch
FAQ
What is CVE-2026-1213?
CVE-2026-1213 is a vulnerability with a CVSS score of 4.3 (MEDIUM). All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12...
How severe is CVE-2026-1213?
CVE-2026-1213 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1213?
Check the references section above for vendor advisories and patch information. Affected products include: Askbot Askbot.