PoC Index

CVE-2021-25991

HIGH 7.3EPSS 0.8%

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

CVSS v3.1
7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CVSS v3.1
5.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
EPSS
0.80% chance of exploitation in the next 30 days, 54th percentile
Published
2021-12-29
Updated
2025-04-30

Proof-of-concept exploits (1)

References

Related