What the vulnerability does
01Description
Missing Authorization vulnerability in MediaRon LLC Custom Query Blocks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Custom Query Blocks: from n/a through 5.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in MediaRon LLC Custom Query Blocks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Custom Query Blocks: from n/a through 5.2.0.
Explanation of Vulnerability in Simple Terms
Custom Query Blocks through version 5.2.0 fails to properly restrict access to sensitive functionality. An unauthenticated attacker can read limited data from the site without authorization. The vulnerability requires only network access and no user interaction. Update to a version newer than 5.2.0 to remediate.
What an attacker can do
Read limited non-public data from the site without logging in.
Potential impact on your site
Sensitive site data may be exposed to unauthenticated visitors.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities