What the vulnerability does
01Description
Missing Authorization vulnerability in Austin Custom Login custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login: from n/a through <= 4.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Austin Custom Login custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login: from n/a through <= 4.1.0.
Explanation of Vulnerability in Simple Terms
Custom Login versions 4.1.0 and earlier lack proper authorization checks, allowing authenticated users to modify settings they should not have access to. An attacker with a low-privilege account can alter configuration without proper permission validation. The vulnerability affects the integrity of site settings but does not expose sensitive data or cause service disruption.
What an attacker can do
Modify Custom Login settings without proper authorization.
Potential impact on your site
Unauthorized users can change plugin configuration, potentially disrupting login behavior or security settings.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities