Improper Authorization in Login Page | Design Login Page | Rebrand Login - CVE-2023-2545

 

Improper Authorization in Login Page | Design Login Page | Rebrand Login - CVE-2023-2545

Published: June 2, 2023


Vulnerability identifier: #VU76821
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-2545
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Login Page | Design Login Page | Rebrand Login
Software vendor:
FeatherPlugins

Description

The vulnerability allows a remote attacker to bypass the authorization mechanisms.

The vulnerability exists due to a missing capability check in the "getListOfUsers" function. A remote user can bypass access restrictions and access the login links, leading to privilege escalation.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links