What the vulnerability does
01Description
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
Explanation of Vulnerability in Simple Terms
PageLayer versions up to 1.8.1 lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a valid account can make requests that exhaust server resources or crash the application, disrupting service for legitimate users. Update to version 2.1.3 or later to restore access controls.
What an attacker can do
Disrupt the site by exhausting server resources or crashing the application.
Potential impact on your site
Site becomes unavailable or unresponsive; legitimate users cannot access PageLayer functionality.
Conditions required to exploit
Attacker must have a valid PageLayer user account with low-level privileges.
Key dates
External resources
Related vulnerabilities