#VU22632 Improper access control in IgniteUp - Coming Soon and Maintenance Mode
Published: November 11, 2019
IgniteUp - Coming Soon and Maintenance Mode
Ceylon Systems
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "removeSubscribers" and "activateTemplate" functions. A remote attacker can bypass implemented security restrictions and delete subscribers or switch the plugin’s template.