CVE-2022-4687
23.12.2022, 12:15
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.Enginsight
Vendor | Product | Version |
---|---|---|
usememos | memos | 𝑥 < 0.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-648 - Incorrect Use of Privileged APIsThe application does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.