What the vulnerability does
01Description
Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3.
Explanation of Vulnerability in Simple Terms
Login As Users versions up to 1.4.3 lack proper authorization checks, allowing authenticated users with low privileges to perform administrative actions they should not have access to. An attacker can read, modify, or delete site data without restriction. The vulnerability requires a valid user account but no additional user interaction.
What an attacker can do
Read, modify, or delete any site data and perform administrative actions without proper authorization.
Potential impact on your site
Any authenticated user can access and modify sensitive data, user accounts, and site settings regardless of their assigned role.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities