What the vulnerability does
01Description
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
Explanation of Vulnerability in Simple Terms
Slider Revolution versions before 6.7.0 lack proper authorization checks, allowing an attacker to perform unauthorized actions by tricking a site visitor into clicking a malicious link. The vulnerability affects confidentiality, integrity, and availability of the site. Update to version 6.7.0 or later to patch this issue.
What an attacker can do
Perform unauthorized actions on the site by tricking a visitor into clicking a link.
Potential impact on your site
Unauthorized changes to site content, data exposure, or service disruption if a visitor is tricked.
Conditions required to exploit
Victim must click an attacker-supplied link; no authentication required.
Key dates
External resources
Related vulnerabilities