Headline
GHSA-ghx2-6v4g-9wmm: usememos/memos makes Incorrect Use of Privileged APIs
In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via API DELETE https://demo.usememos.com/api/memo/$idnote
. The vulnerability will lose all user notes data throughout the system, causing damage to user data.
usememos/memos makes Incorrect Use of Privileged APIs
High severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022