Filtered by vendor Flagsmith Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-52872 1 Flagsmith 1 Flagsmith 2024-11-18 7.5 High
In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.
CVE-2024-52871 1 Flagsmith 1 Flagsmith 2024-11-18 7.5 High
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.