What the vulnerability does
01Description
Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.
Explanation of Vulnerability in Simple Terms
ACF Galerie 4 through version 1.4.2 lacks proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with low-level account privileges can alter data without restriction. The vulnerability affects the integrity of site content but does not expose sensitive information or cause service disruption.
What an attacker can do
Modify or alter content on the site without proper permission checks.
Potential impact on your site
Unauthorized users can alter gallery content or other protected data, compromising content integrity.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities