PT-2025-52492 · Galette · Galette
Trasher
·
Published
2025-12-19
·
Updated
2026-01-05
·
CVE-2025-58053
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Galette versions prior to 1.2.0
Description
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, it was possible to gain higher privileges by updating an existing account using a self-forged POST request. The issue was addressed in version 1.2.0. The application accepts POST requests to update account information, and improper validation of the request data allowed an attacker to manipulate account privileges. The vulnerable operation involves submitting a crafted POST request to modify account details, potentially elevating the user's role within the system.
Recommendations
Update to version 1.2.0 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Galette