← Πίσω στην αναζήτηση CVE

CVE-2026-48783

Περιγραφή

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token-s claims, without verifying the token-s intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller-s own organization, including adjusting team-member enablement state, disabling integrations exceeding the asserted plan-s limits, and resetting the scheduled-post cron when the asserted plan was the free tier. Impact is limited to the attacker-s own organization and cannot be redirected at other tenants through this endpoint. This issue has been fixed in version 2.21.8.

CVSS 4.8EPSS 0.16999999999999998%Κίνδυνος 0.49
Προβολή πηγής
Δημοσίευση
2026-06-17 13:20:43
Διάνυσμα
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L