PT-2025-49567 · Unknown · Usememos/Memos
CVE-2025-65798
·
Publicado
2025-12-08
·
Atualizado
2026-07-30
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
usememos memos version 0.25.2
Description
A flaw in access control within usememos memos allows attackers with limited privileges to improperly change or remove attachments uploaded by other users. The issue involves insufficient restrictions on user permissions related to attachment management.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Usememos/Memos