PT-2021-16914 · Ifme · Ifme
Published
2021-12-29
·
Updated
2022-01-10
·
CVE-2021-25991
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ifme versions v5.0.0 through v7.32
Description
The issue is related to improper access control, allowing admins to ban themselves. This leads to deactivation from the Ifme account and complete loss of admin access to Ifme.
Recommendations
For versions v5.0.0 through v7.32, consider restricting admin access to the self-ban functionality as a temporary workaround until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ifme