What the vulnerability does
01Description
Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.
Explanation of Vulnerability in Simple Terms
Google Maps CP versions up to 1.0.43 lack proper authorization checks, allowing authenticated users to modify map data or settings they should not have access to. An attacker with low-level site access can alter maps without appropriate permission validation. The vulnerability affects integrity but not confidentiality or availability.
What an attacker can do
Modify map data or settings without proper authorization.
Potential impact on your site
Unauthorized users can alter maps, potentially defacing or corrupting map content visible to site visitors.
Conditions required to exploit
Attacker must have a low-level authenticated account on the site.
Key dates
External resources
Related vulnerabilities