What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.
Explanation of Vulnerability in Simple Terms
WTI Like Post versions up to 1.4.6 contain an authentication bypass vulnerability. An attacker can modify data without authentication by exploiting insufficient input validation. The vulnerability allows unauthorized changes to site content or settings. Update to a version newer than 1.4.6 to resolve this issue.
What an attacker can do
Modify site data or content without logging in.
Potential impact on your site
Unauthorized users can alter posts, settings, or other data managed by the WTI Like Post component.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities