PT-2026-50122 · Postiz · Postiz
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Postiz versions prior to 2.21.8
Description
Postiz contains an unauthenticated billing-enforcement bypass. The endpoint '/public/modify-subscription' accepts a signed token and applies subscription-enforcement side effects to the organization referenced in the token's claims without verifying the token's intended purpose. While the persisted subscription tier cannot be changed, the issue allows the execution of enforcement-related side effects on the caller's own organization. These effects include adjusting team-member enablement state, disabling integrations that exceed the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan is the free tier. The impact is limited to the attacker's own organization and cannot be redirected to other tenants.
Recommendations
Update to version 2.21.8.
As a temporary workaround, restrict access to the '/public/modify-subscription' endpoint.
Exploit
Fix
Insufficient Verification of Data Authenticity
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postiz