What the vulnerability does
01Description
Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.
Explanation of Vulnerability in Simple Terms
Buy Me a Coffee version 3.7 and earlier lacks proper authorization checks, allowing an attacker to modify data through a crafted request. The vulnerability requires user interaction—typically clicking a malicious link—and does not expose sensitive information or disrupt service availability. Site owners should update to a version newer than 3.7 when available.
What an attacker can do
Modify site data or settings by tricking a user into clicking a malicious link.
Potential impact on your site
Unauthorized changes to site content or configuration if a user is socially engineered.
Conditions required to exploit
Victim must click an attacker-supplied link; no authentication required.
Key dates
External resources
Related vulnerabilities