What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0.
Explanation of Vulnerability in Simple Terms
Homey Login Register versions 2.4.0 and earlier contain a critical vulnerability that allows unauthenticated attackers to read and modify sensitive data or run their own code on the site. No user interaction or special network access is required. The vulnerability stems from insufficient access controls in the component.
What an attacker can do
Read or modify any data on the site, or run their own code without logging in.
Potential impact on your site
Complete compromise of the site and all user data; attacker can take full control.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities