What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS Hide Login: from n/a through 2.1.8.
Explanation of Vulnerability in Simple Terms
02Summary
LWS Hide Login versions up to 2.1.8 expose sensitive information through improper access controls. An attacker can retrieve login page details without authentication, though significant effort is required. The exposure is limited to confidentiality; integrity and availability are not affected. Update to a version newer than 2.1.8.
What an attacker can do
03Attacker Capabilities
Retrieve sensitive login page information without authentication.
Potential impact on your site
04Site Impact
Login page details may be exposed to unauthenticated visitors, potentially aiding reconnaissance.
Conditions required to exploit
05Prerequisites
Network access; no authentication required, but exploitation requires high attack complexity.
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated