CVE-2021-25991
HIGH 7.3EPSS 0.8%
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
- CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H - CVSS v3.1
- 5.7 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H - CVSS v2.0
- 4.9 MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:P - EPSS
- 0.80% chance of exploitation in the next 30 days, 54th percentile
- Published
- 2021-12-29
- Updated
- 2025-04-30