What the vulnerability does
01Description
Missing Authorization vulnerability in appsbd Simple Notification simple-notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Notification: from n/a through <= 1.3.
Explanation of Vulnerability in Simple Terms
02Summary
Simple Notification versions 1.3 and earlier lack proper authorization checks, allowing authenticated users to perform actions they should not have access to. The vulnerability requires user interaction and can affect confidentiality, integrity, and availability across the application scope. Update to a version newer than 1.3 to remediate.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions affecting data confidentiality, integrity, and availability within the application.
Potential impact on your site
04Site Impact
Authenticated users could bypass access controls and perform actions outside their intended permissions, risking data exposure or modification.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
May 11, 2026
Record updated