Impact
An issue in the billing and license activation subsystem of Postiz App allows remote attackers to bypass payment authorization by forging or replaying promotional or lifetime‑deal redemption codes. The flaw arises from insufficient cryptographic verification and the absence of server‑side state checks (CWE‑345), enabling attackers to create valid tokens or reuse single‑use ones to activate permanent, top‑tier paid subscriptions without any payment. The likely attack vector is remote exploitation through the subscription activation API using forged or replayed redemption codes.
Affected Systems
The affected product is Postiz App developed by GitroomHQ. The vulnerability was addressed in release v2.21.10; older versions lack the fix, but no specific version range was enumerated in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. However, the flaw permits unauthenticated remote attackers to grant themselves or others paid access, potentially causing significant financial loss. The attack requires only the ability to request the billing API; there is no prerequisite of authentication, making the exploit relatively low effort.
OpenCVE Enrichment