What the vulnerability does
01Description
Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117.
Explanation of Vulnerability in Simple Terms
Simple URLs versions 117 and earlier lack proper authorization checks, allowing authenticated users to modify or delete URL records they should not have access to. An attacker with a low-privilege account can alter the integrity of URL mappings or cause denial of service by removing entries. No confidentiality breach occurs. Update to a version newer than 117.
What an attacker can do
Modify or delete URL records belonging to other users or the site.
Potential impact on your site
Authenticated users can tamper with URL mappings, disrupting site navigation or removing important redirects.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities