Ad

CVE-2026-48783

MEDIUM CVSS 3.1: 4,8 EPSS 0.17%
Обновлено 17 июня 2026
Postiz
Параметр Значение
CVSS 4,8 (MEDIUM)
Уязвимые версии до 2.21.8
Устранено в версии 2.21.8
Тип уязвимости CWE-862 (Отсутствие авторизации), CWE-639 (Обход авторизации), CWE-345 (Недостаточная проверка данных), CWE-749
Поставщик Postiz
Публичный эксплойт Нет

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller's own organization, including adjusting team-member enablement state, disabling integrations exceeding the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan was the free tier.

Impact is limited to the attacker's own organization and cannot be redirected at other tenants through this endpoint. This issue has been fixed in version 2.21.8.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Высокая
Сложно эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Низкое
Частичная модификация данных
Доступность
Низкое
Частичное нарушение работы

Строка CVSS v3.1