What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.
Explanation of Vulnerability in Simple Terms
CGC Maintenance Mode through version 1.2 contains an authentication bypass vulnerability. An attacker on the network can access sensitive information by exploiting improper authentication checks, even without valid credentials. The vulnerability has low confidentiality impact and requires specific conditions to exploit. Site administrators should update to a version newer than 1.2.
What an attacker can do
Access sensitive information without valid credentials by bypassing authentication checks.
Potential impact on your site
Unauthorized users may view sensitive data if the plugin is active on your site.
Conditions required to exploit
Network access; specific conditions required (high attack complexity).
Key dates
External resources
Related vulnerabilities