Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r2jv-fwfr-4j8c | askbot inexhaustive permissions check allows any user to modify a different user's profile picture |
Tue, 14 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:askbot:askbot:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 27 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2. | |
| Title | Askbot 0.12.2 - Insecure Direct Object Reference (IDOR) | |
| First Time appeared |
Askbot
Askbot askbot |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:askbot:askbot:0.12.2:*:linux:*:*:*:*:* cpe:2.3:a:askbot:askbot:0.12.2:*:macos:*:*:*:*:* cpe:2.3:a:askbot:askbot:0.12.2:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Askbot
Askbot askbot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-01-27T20:48:18.851Z
Reserved: 2026-01-19T21:32:48.977Z
Link: CVE-2026-1213
Updated: 2026-01-27T20:48:15.393Z
Status : Analyzed
Published: 2026-01-27T14:15:55.887
Modified: 2026-04-14T14:58:57.673
Link: CVE-2026-1213
No data.
OpenCVE Enrichment
Updated: 2026-04-18T15:00:03Z
Github GHSA