What the vulnerability does
01Description
Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.
Explanation of Vulnerability in Simple Terms
Gallery Images Ape through version 2.2.8 fails to properly check user permissions before allowing modifications to gallery data. A logged-in user with low privileges can alter gallery content they should not have access to. The vulnerability does not expose sensitive data or crash the site, but allows unauthorized changes to published galleries.
What an attacker can do
Modify gallery content without proper authorization.
Potential impact on your site
Unauthorized users can alter or deface gallery images and metadata, requiring manual restoration.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities