usememos/memos makes Incorrect Use of Privileged APIs
Discription

In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via `API DELETE https://demo.usememos.com/api/memo/$idnote`. The vulnerability will lose all user notes data throughout the system, causing damage to user data.Read More

Back to Main

Subscribe for the latest news: