Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-hc5q-26h8-r9wf: usememos/memos Improper Authorization vulnerability

In usememos/memos 0.9.0 and prior, an unauthorized user can access any private memo by URL hacking a memo on the editing screen.

ghsa
#vulnerability#git#auth
GHSA-pp3p-6jjh-rmg7: usememos/memos Improper Access Control vulnerability

An Improper Access Control vulnerability in usememos/memos 0.9.0 and prior can result in a user deleting others' public and private memos.

GHSA-6w5w-wx8w-2cq9: usememos/memos Improper Access Control vulnerability

usememos/memos 0.9.0 and prior is vulnerable to full account takeover via changing user name, email address, and display name.

GHSA-qf9q-3wwx-8qjv: usememos/memos Improper Access Control vulnerability

In usememos/memos 0.9.0 and prior, a user can view any content from private memos from other users via the API.

GHSA-m5pr-wm6q-x4g2: usememos/memos vulnerable to Comparison of Object References Instead of Object Contents

Comparison of Object References Instead of Object Contents in GitHub repository usememos/memos 0.9.0 and prior.

GHSA-gfj4-wg89-m22r: usememos/memos Improper Access Control vulnerability

In usememos/memos 0.9.0 and prior, users can edit and delete all other users' shortcuts.

GHSA-ghx2-6v4g-9wmm: usememos/memos makes Incorrect Use of Privileged APIs

In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via `API DELETE https://demo.usememos.com/api/memo/$idnote`. The vulnerability will lose all user notes data throughout the system, causing damage to user data.

GHSA-mfvq-m3jj-8864: usememos/memos vulnerable to Improper Verification of Source of a Communication Channel

usememos/memos 0.9.0 and prior is vulnerable to Improper Verification of Source of a Communication Channel.

GHSA-qrrf-xvcf-p64q: usememos/memos vulnerable Improper Restriction of Excessive Authentication Attempts

In usememos/memos 0.9.0 and prior, an attacker can delete other users' posts via post id, which can be done via brute force.

GHSA-f83p-pg86-p922: usememos/memos has Insufficient Granularity of Access Control

usememos/memos 0.9.0 and prior allows an attacker to archive any user's public or private post.