Intel

AIKIDO-2024-10397

appsero/client is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

80

High Risk

This Affects:

phpappsero/client
1.0 - 2.0.0
Fixed in 2.0.1

TL;DR

Affected versions of this package are vulnerable to improper access control, which allows lower-privileged users to execute plugin settings without the required permissions. This can lead to unauthorized configuration changes or actions being performed by users with insufficient privileges.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

appsero/client is vulnerable to Improper Access Control in versions 1.0 - 2.0.0.

How to fix this

Upgrade the appsero/client library to the patch version.