What the vulnerability does
01Description
Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.
Explanation of Vulnerability in Simple Terms
de:branding versions 1.0.2 and earlier contain a missing authentication vulnerability that allows an authenticated user with low privileges to read, modify, or delete data on the site. The vulnerability requires network access and low-level user credentials but no additional user interaction. An attacker can escalate their capabilities beyond their intended permission level.
What an attacker can do
Read, modify, or delete sensitive data on the site with only low-level user credentials.
Potential impact on your site
Any low-privilege user (subscriber, contributor, etc.) can access or alter data they should not be able to reach.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; network access required.
Key dates
External resources
Related vulnerabilities