What the vulnerability does
01Description
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Explanation of Vulnerability in Simple Terms
Internal Link Optimiser versions up to 5.2.7 lack proper authorization checks, allowing unauthenticated attackers to read and modify link data. The vulnerability requires no user interaction and is exploitable over the network. An attacker can access or alter internal link configurations without permission.
What an attacker can do
Read and modify internal link data without authentication.
Potential impact on your site
Attackers can view and alter your site's internal link structure and configurations without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities