-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows both functions lacked security decorators and permission checks prior to patching. The vulnerability report specifically mentions unauthorized access via /api/user/<id> and /api/group/<id> routes. The added @login_required decorator and admin permission checks in the patch directly address these authorization flaws, confirming these were the vulnerable endpoints.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| EVE-SRP | pip | < 0.12.12 | 0.12.12 |
Ongoing coverage of React2Shell