What the vulnerability does
01Description
Missing Authorization vulnerability in M.Code Url Rewrite Analyzer url-rewrite-analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Url Rewrite Analyzer: from n/a through <= 1.3.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Url Rewrite Analyzer through version 1.3.3 lacks proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with valid login credentials can make requests that degrade site availability. The vulnerability requires authentication but no special user role, making it accessible to any registered user.
What an attacker can do
03Attacker Capabilities
Authenticated user can degrade site availability by triggering resource exhaustion.
Potential impact on your site
04Site Impact
Any registered user can cause temporary service disruption or performance degradation.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges; no special role required.
Key dates
06Disclosure timeline
May 19, 2025
CVE published
April 28, 2026
Record updated