What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <= 3.5.16.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <= 3.5.16.
Explanation of Vulnerability in Simple Terms
Modal Dialog versions 3.5.16 and earlier contain a code injection vulnerability that allows high-privileged users to execute arbitrary code on the site. The vulnerability affects the scope beyond the component itself. An attacker with administrative or equivalent access can inject and run malicious code, potentially compromising the entire site.
What an attacker can do
Run arbitrary code on the site with full system access.
Potential impact on your site
A compromised admin account can execute code affecting the entire site, data, and users.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent role) and network access.
Key dates
External resources
Related vulnerabilities