What the vulnerability does
01Description
Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Engine: from n/a through 6.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Engine: from n/a through 6.4.0.
Explanation of Vulnerability in Simple Terms
Photo Engine through version 6.4.0 contains an authorization flaw that allows authenticated users to trigger a denial-of-service condition. An attacker with low-level account access can make requests that degrade site availability. The vulnerability requires valid login credentials but no special privileges.
What an attacker can do
Authenticated user can make requests that degrade site availability or cause service disruption.
Potential impact on your site
Authenticated users can disrupt site performance or availability without admin privileges.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities