What the vulnerability does
01Description
Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through <= 1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through <= 1.2.
Explanation of Vulnerability in Simple Terms
Loginplus versions 1.2 and earlier contain an authorization bypass that allows unauthenticated attackers to trigger a denial-of-service condition over the network. The vulnerability stems from missing access controls on a functionality that can be invoked without authentication. No user interaction is required to exploit this issue.
What an attacker can do
Trigger a denial-of-service condition on the site without authentication.
Potential impact on your site
Site availability may be disrupted by unauthenticated attackers making repeated requests to the vulnerable endpoint.
Conditions required to exploit
Network access to the Loginplus application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities