CVE-2025-59950
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double clicks on a button inside an attacker-controlled website. A successful attack can allow the attacker to promote themselves to "admin" and log into other users' accounts; the attacker has to know the specific instance URL they're targeting. This issue is fixed in version 1.27.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
- EPSS probability
- 0.28%
- CWE
- CWE-1021
- Published
- 2025-09-29
- Last modified
- 2026-03-13
Affected products
- FreshRSS FreshRSS
Weakness type
Related vulnerabilities
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-87538 — Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had...
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87486 — Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed...
- CVE-2026-75548 — Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console
- CVE-2026-70608 — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path