What the vulnerability does
01Description
Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.
Explanation of Vulnerability in Simple Terms
02Summary
Super Progressive Web Apps versions 2.2.21 and earlier lack proper authorization checks, allowing an unauthenticated attacker to trigger a denial-of-service condition by making the site unresponsive. The attack requires the victim to visit a malicious link. The availability impact is limited and does not affect data confidentiality or integrity.
What an attacker can do
03Attacker Capabilities
Make the site temporarily unresponsive or slow by triggering resource exhaustion.
Potential impact on your site
04Site Impact
Site may become slow or unresponsive during an attack, but data is not exposed or modified.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link; no authentication required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
May 11, 2026
Record updated