Improper Authorization in Login Page | Design Login Page | Rebrand Login - CVE-2023-2547

 

Improper Authorization in Login Page | Design Login Page | Rebrand Login - CVE-2023-2547

Published: June 2, 2023


Vulnerability identifier: #VU76818
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-2547
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Login Page | Design Login Page | Rebrand Login
Software vendor:
FeatherPlugins

Description

The vulnerability allows a remote attacker to bypass the authorization mechanisms.

The vulnerability exists due to a missing capability check in the "deleteUser" function. A remote user can bypass access restrictions and delete the temp user generated by the plugin.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links