What the vulnerability does
01Description
Missing Authorization vulnerability in Layered If Menu.This issue affects If Menu: from n/a through 0.16.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Layered If Menu.This issue affects If Menu: from n/a through 0.16.3.
Explanation of Vulnerability in Simple Terms
If Menu versions up to 0.16.3 lack proper authorization checks, allowing unauthenticated attackers to modify menu data over the network. The vulnerability does not expose sensitive information but can corrupt or alter menu configurations. No user interaction is required to exploit this issue.
What an attacker can do
Modify menu data without authentication.
Potential impact on your site
Menu configurations can be altered or corrupted by unauthorized parties, potentially disrupting site navigation.
Conditions required to exploit
Network access to the affected If Menu instance; no authentication required.
Key dates
External resources
Related vulnerabilities