Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948 | third party advisory patch |
https://huntr.dev/bounties/25de88cc-8d0d-41a1-b069-9ef1327770bc | exploit third party advisory patch |