What the vulnerability does
01Description
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.
Explanation of Vulnerability in Simple Terms
PDF Poster through version 2.4.1 fails to properly check user permissions before allowing access to sensitive functions. An unauthenticated attacker can read limited data from the site without needing to log in or interact with a user. Update to a version newer than 2.4.1.
What an attacker can do
Read limited non-public data from the site without authentication.
Potential impact on your site
Sensitive information may be exposed to unauthenticated visitors.
Conditions required to exploit
Network access only; no login or user interaction required.
Key dates
External resources
Related vulnerabilities