What the vulnerability does
01Description
Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.
Explanation of Vulnerability in Simple Terms
Google Typography through version 1.1.2 fails to properly check user permissions before allowing modifications to typography settings. An authenticated user with low privileges can alter typography configurations that should be restricted to administrators. The vulnerability does not expose sensitive data or cause service disruption, but allows unauthorized changes to site appearance and styling.
What an attacker can do
Modify typography settings without proper authorization.
Potential impact on your site
Unauthorized users can change site typography and styling settings intended for administrators only.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities