CVE-2021-25991
Summary
| CVE | CVE-2021-25991 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-29 09:15:00 UTC |
| Updated | 2022-01-10 16:29:00 UTC |
| Description | In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [#2052] Fix improper access control leads to admin self-banning · ifmeorg/ifme@d1f570c · GitHub | CONFIRM | github.com | |
| CVE-2021-25991 | WhiteSource Vulnerability Database | MISC | www.whitesourcesoftware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: WhiteSource Vulnerability Research Team (WVR)
There are currently no legacy QID mappings associated with this CVE.