What the vulnerability does
01Description
Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.
Explanation of Vulnerability in Simple Terms
MJ Update History versions up to 1.0.4 lack proper access controls on sensitive functions. An authenticated user with low privileges can read data they should not have access to. The vulnerability requires a valid login but no special permissions. Update to a version newer than 1.0.4 to resolve this issue.
What an attacker can do
Read sensitive data they should not have access to.
Potential impact on your site
Authenticated users can access confidential information beyond their permission level.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site.
Key dates
External resources
Related vulnerabilities