Impact
A flaw in the light0011 CMS ChapterController allows an attacker to bypass normal authorization checks by manipulating arguments sent to the ChapterController.class.php file. The vulnerability is based on improper authentication enforcement (CWE-285) and insufficient verification of the caller’s authority (CWE-639). If successful, an attacker could access or modify content intended only for higher‑privileged roles, potentially compromising the confidentiality, integrity, and availability of site data.
Affected Systems
The affected product is light0011 CMS, specifically the Chapter Controller component. No specific version numbers are listed, as the project follows a rolling release cycle and the patch status is unknown.
Risk and Exploitability
The CVSS score of 6.9 signals a moderate risk, and the EPSS score is not available, so current exploitation probability is unknown. The vulnerability can be exploited remotely via crafted requests to the ChapterController endpoints, and public disclosures confirm that it is usable. The absence of a KEV listing indicates that it has not yet been identified as a known exploited vulnerability in the wild.
OpenCVE Enrichment