Themes Vulnerabilities

Himer - Social Questions and Answers < 2.1.1 - Subscriber+ Private Group Joining via IDOR

Description

The theme allows any authenticated user to join a private group due to a missing authorization check on a function

Proof of Concept

Affects Themes

Fixed in 2.1.1

References

YouTube Video

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Sushmita Poudel
Submitter
Sushmita Poudel
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2024-06-12 (about 1 year ago)
Added
2024-06-12 (about 1 year ago)
Last Updated
2025-08-21 (about 4 months ago)

Other