1111
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via craft…
|
CWE-862
Missing Authorization
|
CVE-2025-26376
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1112
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrar…
|
CWE-862
Missing Authorization
|
CVE-2025-26375
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1113
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate…
|
CWE-862
Missing Authorization
|
CVE-2025-26374
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1114
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate …
|
CWE-862
Missing Authorization
|
CVE-2025-26373
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1115
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from gr…
|
CWE-862
Missing Authorization
|
CVE-2025-26372
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1116
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups …
|
CWE-862
Missing Authorization
|
CVE-2025-26371
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1117
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges fr…
|
CWE-862
Missing Authorization
|
CVE-2025-26370
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1118
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to us…
|
CWE-862
Missing Authorization
|
CVE-2025-26369
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1119
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups v…
|
CWE-862
Missing Authorization
|
CVE-2025-26368
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1120
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create arbitrary use…
|
CWE-862
Missing Authorization
|
CVE-2025-26367
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|