Lucene search

K
osvGoogleOSV:CVE-2021-25973
HistoryNov 02, 2021 - 7:15 a.m.

CVE-2021-25973

2021-11-0207:15:07
Google
osv.dev
2
publify
access control
user registration

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

31.3%

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

31.3%