Vulnerabilities
Vulnerable Software
Galette:  >> Galette  >> 1.0.2  Security Vulnerabilities
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass intended restrictions allowing unauthorized access and changes despite role-based controls. Since it requires privileged access initially, exploitation is restricted to malicious insiders or compromised group managers accounts. Version 1.2.0 fixes the issue.
CVSS Score
8.1
EPSS Score
0.001
Published
2025-12-19
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-12-19
Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue is fixed in version 1.2.0.
CVSS Score
5.4
EPSS Score
0.001
Published
2025-11-04
Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This issue is fixed in version 1.2.0.
CVSS Score
6.1
EPSS Score
0.001
Published
2025-11-04


Contact Us

Shodan ® - All rights reserved