What the vulnerability does
01Description
Missing Authorization vulnerability in Fahad Mahmood Injection Guard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Injection Guard: from n/a through 1.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Fahad Mahmood Injection Guard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Injection Guard: from n/a through 1.2.1.
Explanation of Vulnerability in Simple Terms
Injection Guard through version 1.2.1 fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability does not expose sensitive information or crash the system, but allows unauthorized changes to site content or settings.
What an attacker can do
Modify data or settings without proper authorization.
Potential impact on your site
Unauthorized users can alter site content or configuration within their privilege scope.
Conditions required to exploit
Attacker must be logged in with a low-privilege account.
Key dates
External resources
Related vulnerabilities