What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
Explanation of Vulnerability in Simple Terms
The miniOrange Malware Scanner plugin through version 4.7.1 exposes sensitive information to unauthenticated attackers over the network. An attacker can read non-critical data without needing to log in or interact with a site administrator. The vulnerability stems from improper authentication checks on certain endpoints. Update to a version newer than 4.7.1.
What an attacker can do
Read sensitive information from the plugin without logging in.
Potential impact on your site
Attackers can access non-critical plugin data without a valid account.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities