What the vulnerability does
01Description
Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.
Explanation of Vulnerability in Simple Terms
Simple File List through version 6.1.9 does not properly check user permissions before allowing file operations. An unauthenticated attacker can make requests to the plugin that cause the site to become unavailable or unresponsive. No authentication or user interaction is required to trigger the vulnerability.
What an attacker can do
Make the site unavailable or unresponsive without needing to log in.
Potential impact on your site
Your site may become unavailable or slow due to resource exhaustion from unauthenticated requests.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities