What the vulnerability does
01Description
Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.
Explanation of Vulnerability in Simple Terms
Popup Maker versions up to 1.19.2 lack proper authorization checks, allowing unauthenticated attackers to modify popup content and settings. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update to a version newer than 1.19.2 to restore access controls.
What an attacker can do
Modify popup content and settings without authentication.
Potential impact on your site
Popups can be altered by anyone to display malicious content, phishing, or spam.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities