In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via API DELETE https://demo.usememos.com/api/memo/$idnote. The vulnerability will lose all user notes data throughout the system, causing damage to user data.
{
"github_reviewed": true,
"github_reviewed_at": "2022-12-30T19:48:54Z",
"nvd_published_at": "2022-12-28T14:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-648"
]
}