Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53 | third party advisory patch |
https://huntr.dev/bounties/aa45a6eb-cc38-45e5-a301-221ef43c0ef8 | patch third party advisory exploit |