Skip to content

Guild member objects can be edited regardless of right/permission.

Moderate
MaddyUnderStars published GHSA-9q7f-pv47-cxp9 Feb 2, 2023

Package

fosscord-server (fosscord-server)

Affected versions

all

Patched versions

51239d60f669ddfe18739e0e05cf713ef88a38ed

Description

Summary

A PATCH request to /guilds/:id/members/:id allows any user regardless of rights to edit any other user's nickname, guild profile bio, or guild avatar.

Mitigation

This is fixed as of commit 51239d6

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits