Q-Free MaxTime Missing Authorization Vulnerability in User Groups Management

Vulnerability

A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to add users to groups by sending crafted HTTP requests. The issue is located in the user-groups routing file of the application.

Impact

Exploitation of this vulnerability could lead to unauthorized user group modifications, allowing attackers to gain access to restricted resources or privileges.

Remediation

No official patch is available from the vendor. As a temporary measure, it is recommended to review user and group configurations in the management web application for Q-Free MaxTime versions through 2.11.0, ensuring all settings are correct. Additionally, review all user accounts in the same application and remove any unnecessary ones.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.