Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2021-25992
Disclosure Date: February 08, 2022 (last updated February 23, 2025)
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.
0
Attacker Value
Unknown
CVE-2021-25991
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
0
Attacker Value
Unknown
CVE-2021-25989
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
0
Attacker Value
Unknown
CVE-2021-25990
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
0
Attacker Value
Unknown
CVE-2021-25988
Disclosure Date: December 26, 2021 (last updated February 23, 2025)
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
0