PT-2026-60793 · Git+1 · Maybe
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Maybe versions prior to 0.6.0
Description
Authenticated users with low-privilege member roles can access and modify global hosting settings. This occurs because the
ensure admin filter is only applied to the clear cache action within the Settings::HostingsController, leaving the show and update actions unprotected. An attacker can exploit this to read the operator's Synth API key in plaintext, overwrite it with a custom value, toggle public registration settings, and disable email confirmation requirements.Recommendations
Update to version 0.6.0 or later.
Restrict access to the
Settings::HostingsController to prevent unauthorized users from accessing the show and update actions.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maybe