What the vulnerability does
01Description
Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: from n/a through <= 2.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: from n/a through <= 2.3.1.
Explanation of Vulnerability in Simple Terms
Joy Of Text Lite versions 2.3.1 and earlier lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with a low-privilege account can alter data through the application's interface. The vulnerability affects the integrity of user-generated content but does not expose sensitive information or disrupt availability.
What an attacker can do
Modify or alter content in the application without proper authorization.
Potential impact on your site
Unauthorized changes to site content by authenticated users with limited permissions.
Conditions required to exploit
Attacker must have a valid low-privilege user account and network access to the application.
Key dates
External resources
Related vulnerabilities