What the vulnerability does
01Description
Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.
Explanation of Vulnerability in Simple Terms
Meta Tag Manager versions 3.1 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read sensitive metadata they should not access. The vulnerability requires a valid user account but no special interaction. Confidentiality is at risk; integrity and availability are not affected.
What an attacker can do
Read metadata that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can view sensitive metadata, potentially exposing configuration or content details.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities