Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-ghx2-6v4g-9wmm: usememos/memos makes Incorrect Use of Privileged APIs

In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via API DELETE https://demo.usememos.com/api/memo/$idnote. The vulnerability will lose all user notes data throughout the system, causing damage to user data.

ghsa
#vulnerability#git

usememos/memos makes Incorrect Use of Privileged APIs

High severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022

ghsa: Latest News

GHSA-3m86-c9x3-vwm9: Graylog vulnerable to privilege escalation through API tokens