What the vulnerability does
01Description
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.5.3.
Explanation of Vulnerability in Simple Terms
02Summary
ApplyOnline versions up to 2.5.3 lack proper authorization checks on certain functions. A logged-in user with low privileges can access data or perform actions they should not be permitted to. The vulnerability requires valid site credentials but does not require user interaction from a victim.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the application without proper authorization.
Potential impact on your site
04Site Impact
Logged-in users may access form data or settings beyond their intended permission level.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege user account on the site.
Key dates
06Disclosure timeline
January 2, 2025
CVE published
April 28, 2026
Record updated