Impact
Gophish users with a valid API key can continue to access the API even when their user account has been locked or is required to change its password, thereby bypassing the relief mechanisms that should restrict access after a security incident. This flaw resides in the authentication middleware and permits persistence of unauthorized API privileges for the compromised account.
Affected Systems
All Gophish installations up to and including version 0.12.1 are affected. The vulnerable component is Gophish’s API authentication middleware. Deployments that rely on Gophish’s API for automated actions are susceptible until a patched version is installed.
Risk and Exploitability
The CVSS score of 8.6 signals a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not yet been reported. The attack vector is inferred to require possession of a valid API key, which an attacker can obtain through credential compromise or misconfiguration. With a key in hand, an attacker can bypass account lockout and forced password change requirements, maintaining persistent API access to the victim’s system.
OpenCVE Enrichment