What the vulnerability does
01Description
Missing Authorization vulnerability in truepushplugin Truepush truepush-free-web-push-notifications.This issue affects Truepush: from n/a through <= 1.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in truepushplugin Truepush truepush-free-web-push-notifications.This issue affects Truepush: from n/a through <= 1.0.8.
Explanation of Vulnerability in Simple Terms
Truepush versions up to 1.0.8 lack proper authorization checks, allowing authenticated users with low privileges to read sensitive data and disrupt service availability. An attacker with a basic user account can access information they should not see and trigger denial-of-service conditions. Update to a version newer than 1.0.8.
What an attacker can do
Read sensitive data and cause service disruption with a low-privilege user account.
Potential impact on your site
Unauthorized data exposure and potential service interruptions affecting site availability.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities