What the vulnerability does
01Description
Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.
Explanation of Vulnerability in Simple Terms
Embed RSS versions 3.1 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read or modify sensitive data they should not access. The vulnerability requires network access and an active user account but no additional user interaction. Impact is limited to confidentiality and integrity of restricted information.
What an attacker can do
Read or modify data they should not have access to within the RSS feed component.
Potential impact on your site
Authenticated users can bypass permission controls to view or alter RSS feed settings and data.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no special network conditions required.
Key dates
External resources
Related vulnerabilities