PT-2022-28106 · Unknown · Usememos/Memos

Published

2022-12-28

·

Updated

2024-08-20

·

CVE-2022-4805

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.1
Description The issue concerns the incorrect use of privileged APIs in the usememos/memos GitHub repository. A user can archive any private memos, delete any shortcut, and edit any shortcut from other users via the API. This allows unauthorized access and modification of sensitive data.
Recommendations For versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the API endpoints that allow archiving, deleting, and editing shortcuts to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4805
GHSA-MQ5Q-GPGV-PWXW
GO-2023-1292

Affected Products

Usememos/Memos