6.5
CVE-2026-19127
- EPSS 0.29%
- Veröffentlicht 06.08.2026 22:16:55
- Zuletzt bearbeitet 07.08.2026 14:16:57
- CVE-Watchlists
- Unerledigt
Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitroomHQ
≫
Produkt
postiz-app
Default Statusunaffected
Version
0
Version <
2.21.10
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.208 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 4cdc9741-f887-419a-a2fd-acbbd2729276 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
https://gadvisory.org/advisories/PSA-2026-NWZN9J
https://github.com/gitroomhq/postiz-app/commit/387d85dabe0223cd930714c19072a0aee58541ca
https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.10