Disabled accounts still work normally in pkp/pkp-lib


Reported on

Sep 23rd 2023


Disabled accounts still work normally

Proof of Concept

The account A is logged in and active. Admin suddenly disabled that account, but account A still works normally.

Video Poc



System integrity is not guaranteed. The user has been disabled, will create actions that should not be there. Privacy will be exposed

We are processing your report and will contact the pkp/pkp-lib team within 24 hours. 2 months ago
We have contacted a member of the pkp/pkp-lib team and are waiting to hear back 2 months ago
Alec Smecher modified the Severity from High (7.4) to Medium (4.3) 2 months ago
The researcher has received a minor penalty to their credibility for miscalculating the severity: -1
Alec Smecher validated this vulnerability 2 months ago
HaiNguyen has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
Alec Smecher marked this as fixed in 3.3.0-16 with commit 32d071 2 months ago
The fix bounty has been dropped
This vulnerability has been assigned a CVE
This vulnerability is scheduled to go public on Nov 1st 2023
2 months ago


oke, thank you

Alec Smecher published this vulnerability a month ago
to join this conversation