CVE-2025-58053
EUVD-2025-20457119.12.2025, 17:15
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| galette | galette | 𝑥 < 1.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration