What the vulnerability does
01Description
Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
Explanation of Vulnerability in Simple Terms
PopupAlly versions up to 2.1.0 lack proper authorization checks, allowing authenticated users with low privileges to modify popup content and settings they should not have access to. An attacker with a basic user account can alter popup configurations, potentially affecting site visitors or other users. Update to version 2.1.7 or later to restore proper access controls.
What an attacker can do
Modify popup content and settings without proper authorization.
Potential impact on your site
Unauthorized users can alter popups, potentially disrupting user experience or injecting malicious content.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities