What the vulnerability does
01Description
Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.
Explanation of Vulnerability in Simple Terms
02Summary
3D Work In Progress versions up to 1.0.3 lack proper authorization checks, allowing authenticated users to disrupt service availability. An attacker with low-level access can trigger a denial-of-service condition affecting the entire application. The vulnerability requires valid login credentials but no special privileges. Update to a version newer than 1.0.3.
What an attacker can do
03Attacker Capabilities
Disrupt service availability for all users by triggering a denial-of-service condition.
Potential impact on your site
04Site Impact
Authenticated users can crash or disable the application, affecting all site visitors and operations.
Conditions required to exploit
05Prerequisites
Valid login credentials (low-level user account); network access to the application.
Key dates
06Disclosure timeline
October 23, 2024
CVE published
May 12, 2026
Record updated