FreshRSS
cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*
- <= 1.26.1
A denial-of-service vulnerability has been identified in FreshRSS versions prior to 1.26.2. This issue causes users to be repeatedly logged out after fetching a malicious feed entry. The vulnerability takes advantage of the application's feed handling, leading to a disruptive logout loop for the affected user.
Exploitation of this vulnerability causes a user's account to be logged out repeatedly, disrupting their session and causing inconvenience.
To reproduce this vulnerability, a feed entry must be crafted that includes a logout URL. This can be done by embedding an iframe that redirects to the logout URL, effectively logging the user out when the feed is fetched. Once the malicious feed entry is loaded, the user will experience repeated logouts.
Users can upgrade to FreshRSS version 1.26.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.