What the vulnerability does
01Description
Missing Authorization vulnerability in bqworks Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider: from n/a through 1.9.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in bqworks Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider: from n/a through 1.9.6.
Explanation of Vulnerability in Simple Terms
Accordion Slider through version 1.9.6 fails to properly check user permissions before allowing modifications to slider content. A logged-in user with low privileges can alter sliders they should not have access to. The vulnerability does not expose sensitive data or crash the site, but allows unauthorized changes to published content.
What an attacker can do
Modify accordion slider content without proper authorization.
Potential impact on your site
Unauthorized users can alter slider content, potentially defacing or corrupting published pages.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities