Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/dca35bde877aab6e64ef51b52e590b5d48f692f9 | third party advisory patch |
https://huntr.dev/bounties/b908377f-a61b-432c-8e6a-c7498da69788 | patch exploit third party advisory issue tracking |