Galette
cpe:2.3:a:galette:galette:*:*:*:*:*:*:*
- >= 1.1.4, < 1.2.0
An access control bypass vulnerability has been identified in Galette, a membership management web application for non-profit organizations. This vulnerability affects users logged in as group managers, allowing them to bypass intended restrictions on Contributions and Transactions. The issue is present in Galette versions 1.1.4 through 1.2.0.
Exploitation of this vulnerability allows group managers to bypass restrictions on Contributions and Transactions, potentially leading to unauthorized modifications or access.
Users can upgrade to Galette version 1.2.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.