What the vulnerability does
01Description
Missing Authorization vulnerability in Space Codes AI for SEO ai-for-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI for SEO: from n/a through <= 1.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Space Codes AI for SEO ai-for-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI for SEO: from n/a through <= 1.2.9.
Explanation of Vulnerability in Simple Terms
Space Codes AI for SEO versions 1.2.9 and earlier lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter settings or content without proper permission validation. The vulnerability requires an existing user account but does not affect data confidentiality or system availability.
What an attacker can do
Modify settings or data in the application without proper authorization.
Potential impact on your site
Unauthorized users can alter application settings or content, potentially disrupting SEO configurations or data integrity.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges.
Key dates
External resources
Related vulnerabilities