PT-2026-57163 · Pypi · Flaskbb
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FlaskBB versions prior to 2.2.1
Description
A logic flaw exists that allows authenticated administrators to delete all built-in authorization groups. This occurs due to a type mismatch in the bulk delete protection check within the management views bulk AJAX endpoint. The system compares received JSON integer group IDs against string literals, which causes the protection check to always pass. This action destroys the forum's permission model and can render the site unusable.
Recommendations
Update FlaskBB to version 2.2.1 or later to apply the fix implemented in commit a5da9a5.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flaskbb