← לוח פגיעויות

CVE-2026-48799

גבוהה 7.7

תיאור (מקור, אנגלית)

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.

מדדים

CVSS 3.1
7.7 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-8/8/2026
CWE
CWE-345, CWE-639

קישורים