What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.
Explanation of Vulnerability in Simple Terms
Molongui versions up to 4.7.7 contain an authorization flaw that allows high-privilege users to modify certain data they should not be able to change. The vulnerability requires an authenticated administrator account and does not affect confidentiality or availability. A patch version has not been publicly identified.
What an attacker can do
A high-privilege user can modify data they are not authorized to change.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can alter restricted settings or data.
Conditions required to exploit
Attacker must have administrator-level access to the Molongui installation.
Key dates
External resources
Related vulnerabilities