← Back

If Me

if-me

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Ifme
ifme

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1If Me
1Ifme
Nov 21, 2024
Feb 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by o...Show more
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.Show less
1If Me
1Ifme
Nov 21, 2024
Dec 29, 2021
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access...Show more
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.Show less
1If Me
1Ifme
Nov 21, 2024
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
1If Me
1Ifme
Nov 21, 2024
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
1If Me
1Ifme
Nov 21, 2024
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.