What the vulnerability does
01Description
Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.
Explanation of Vulnerability in Simple Terms
Plugin Notes Plus versions up to 1.2.7 lack proper authorization checks, allowing authenticated users to modify or delete notes they should not have access to. An attacker with a low-privilege account can alter or remove other users' data without restriction. The vulnerability affects integrity and availability of stored notes.
What an attacker can do
Modify or delete notes belonging to other users without authorization.
Potential impact on your site
Users' notes can be altered or deleted by other authenticated users, compromising data integrity and availability.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities