Gitroom Postiz是Gitroom组织的一个支持内容创作、定时发布、数据分析和团队协作的社交媒体管理平台。 Gitroom Postiz 2.21.10之前版本存在输入验证错误漏洞,该漏洞源于计费和许可证激活子系统对促销/终身优惠兑换码的加密验证不足或缺乏服务端状态验证,攻击者可伪造有效兑换令牌或重放现有的一次性代码,绕过支付授权流程,激活永久最高等级付费订阅。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GitroomHQ | postiz-app | < 2.21.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitroomHQ | postiz-app | 0 ~ 2.21.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet