CVE-2021-25991

MEDIUM

ifme 5.0.0-7.32 - Improper Access Control via Admin Self-Ban

Title source: llm
STIX 2.1

Description

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

References (2)

Core 2

Scores

CVSS v3 5.7
EPSS 0.0081
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
if-me/ifme 5.0.0 - 7.32
Published Dec 29, 2021
Tracked Since Feb 18, 2026