What the vulnerability does
01Description
Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2.
Explanation of Vulnerability in Simple Terms
Evergreen Content Poster versions 1.4.2 and earlier lack proper authorization checks, allowing an unauthenticated attacker to modify or disable site content if they can trick a user into visiting a malicious link. The vulnerability affects data integrity and availability but not confidentiality. Update to a version newer than 1.4.2.
What an attacker can do
Modify or disable site content by tricking a user into clicking a malicious link.
Potential impact on your site
Site content can be altered or disabled without your knowledge if users are socially engineered.
Conditions required to exploit
No authentication required, but the victim must click a link or visit a page controlled by the attacker.
Key dates
External resources
Related vulnerabilities