Vulnerabilities > IF ME > Ifme > 7.21.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-29 | CVE-2021-25988 | Cross-site Scripting vulnerability in If-Me Ifme In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin. | 5.4 |
2021-12-29 | CVE-2021-25989 | Cross-site Scripting vulnerability in If-Me Ifme In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. | 5.4 |
2021-12-29 | CVE-2021-25991 | Unspecified vulnerability in If-Me Ifme In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme. | 7.3 |