Impact
The vulnerability arises in the AuthController::_initialize method of ChapterController.class.php, allowing an attacker to manipulate input and bypass the authorization checks that normally restrict administrative actions. This results in the ability to perform privileged operations without proper authentication, effectively escalating privileges within the CMS.
Affected Systems
The affected product is light0011 CMS, specifically the Chapter Controller component located at App/Admin/Controller/ChapterController.class.php. No specific version information is available because the project uses continuous delivery with rolling releases, and the vendor has not issued a patch or updated releases yet.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the exploit is reported to be publicly available and can be initiated remotely, suggesting that an attacker could readily target vulnerable installations.
OpenCVE Enrichment