What the vulnerability does
01Description
Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33.
Explanation of Vulnerability in Simple Terms
Product Designer through version 1.0.33 lacks proper authorization checks, allowing unauthenticated attackers to disrupt service availability. An attacker can send network requests without authentication to trigger a denial-of-service condition. No user interaction is required. Site administrators should update to a version newer than 1.0.33 when available.
What an attacker can do
Make the site unavailable or unresponsive by sending requests that consume server resources.
Potential impact on your site
Your site may become slow or offline if targeted; no data theft or modification risk from this flaw.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities