What the vulnerability does
01Description
Missing Authorization vulnerability in Mohamed Abd Elhalim Arabic Webfonts arabic-webfonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arabic Webfonts: from n/a through <= 1.4.6.
Explanation of Vulnerability in Simple Terms
02Summary
Arabic Webfonts versions 1.4.6 and earlier lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a basic user account can make requests that degrade site availability. The vulnerability requires valid login credentials but no special interaction from other users.
What an attacker can do
03Attacker Capabilities
Authenticated user can degrade site availability by making requests that consume resources.
Potential impact on your site
04Site Impact
Site availability may be impacted if a low-privilege user account is compromised or misused.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
06Disclosure timeline
December 16, 2024
CVE published
May 11, 2026
Record updated