Unauthorized Access Vulnerability in Galette Membership Management Application
CVE-2025-58052
2.1LOW
What is CVE-2025-58052?
The Galette Membership Management Application, widely used by non-profit organizations, has a vulnerability that allows attackers with a group manager role to bypass intended restrictions. This flaw, present in versions 0.9.6 up to 1.1.9, enables unauthorized access and modifications, undermining the role-based access control mechanisms designed to protect sensitive data. Exploitation is predominantly limited to malicious insiders or compromised accounts, emphasizing the importance of robust account management and monitoring. The vulnerability is addressed in version 1.2.0, which reinforces security protocols to prevent such breaches.
Affected Version(s)
galette >= 0.9.6, < 1.2.0
