CVE-2021-25991

MEDIUM

If-me Ifme < 7.32 - Improper Access Control

Title source: rule
STIX 2.1

Description

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

References (2)

Core 2

Scores

CVSS v3 5.7
EPSS 0.0019
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
if-me/ifme 5.0.0 - 7.32
Published Dec 29, 2021
Tracked Since Feb 18, 2026