CVE-2025-22138 – “QPixel Suggested Edit Queue Privilege Escalation in Q&A-based Community Knowledge-Sharing Software”

The following table lists the changes that have been made to the
CVE-2025-22138 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 13, 2025

    Action Type Old Value New Value
    Added Description @codidact/qpixel is a Q&A-based community knowledge-sharing software. In affected versions when a category is set to private or limited-visibility within QPixel’s admin tools, suggested edits within this category can still be viewed by unprivileged or anonymous users via the suggested edit queue. This issue has not yet been patched and no workarounds are available. Users are advised to follow the development repo for updates.

    ### Patches
    Not yet patched.

    ### Workarounds
    None available. Private or limited-visibility categories should not be considered ways to store sensitive information.

    ### References
    Internal: [SUPPORT-114](https://codidact.atlassian.net/issues/SUPPORT-114)

    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-200
    Added Reference https://github.com/codidact/qpixel/security/advisories/GHSA-pv74-hcg9-65r4
Share the Post:

Related Posts