Vulnerabilities
Vulnerable Software
If-Me:  >> Ifme  >> 3.5.0  Security Vulnerabilities
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.
CVSS Score
9.8
EPSS Score
0.004
Published
2022-02-10
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-12-29
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-12-29


Contact Us

Shodan ® - All rights reserved