Q-Free MaxTime Missing Authorization Vulnerability Allowing Unauthorized User Data Modification

Vulnerability

A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to modify user data by sending crafted HTTP requests. The issue is located in the 'maxprofile/users/routes.lua' file.

Impact

Exploitation of this vulnerability could lead to unauthorized modifications of user data, including changes to credentials or permissions.

Remediation

Until an official patch is released, it is recommended to periodically review user and group configurations in the management web application for Q-Free MaxTime versions through 2.11.0. Confirm that all settings are as expected and remove any unnecessary accounts.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.