What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.
Explanation of Vulnerability in Simple Terms
PrivateContent versions 8.11.5 and earlier contain an authentication bypass vulnerability. An attacker can gain unauthorized access to the system without valid credentials, potentially reading, modifying, or deleting sensitive data. The vulnerability requires no user interaction and can be exploited remotely over the network.
What an attacker can do
Bypass authentication and gain full access to read, modify, or delete data without valid credentials.
Potential impact on your site
Attackers can access, modify, or delete any data protected by PrivateContent without logging in.
Conditions required to exploit
Network access to the affected PrivateContent installation. No authentication or user interaction required.
Key dates
External resources
Related vulnerabilities