Vulnerabilities > IF ME

DATE CVE VULNERABILITY TITLE RISK
2022-02-10 CVE-2021-25992 Insufficient Session Expiration vulnerability in If-Me Ifme
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout.
network
low complexity
if-me CWE-613
critical
9.8
2021-12-29 CVE-2021-25988 Cross-site Scripting vulnerability in If-Me Ifme
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
network
low complexity
if-me CWE-79
5.4
2021-12-29 CVE-2021-25989 Cross-site Scripting vulnerability in If-Me Ifme
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor.
network
low complexity
if-me CWE-79
5.4
2021-12-29 CVE-2021-25990 Cross-site Scripting vulnerability in If-Me Ifme
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
network
low complexity
if-me CWE-79
5.4
2021-12-29 CVE-2021-25991 Unspecified vulnerability in If-Me Ifme
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
network
low complexity
if-me
7.3