Medium severity4.3NVD Advisory· Published Jan 27, 2026· Updated Apr 14, 2026
CVE-2026-1213
CVE-2026-1213
Description
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
askbotPyPI | < 0.12.3 | 0.12.3 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295dnvdPatchWEB
- fluidattacks.com/advisories/ghostnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r2jv-fwfr-4j8cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-1213ghsaADVISORY
- askbot.comghsaWEB
- askbot.comnvdProduct
News mentions
0No linked articles in our index yet.