PT-2024-23895 · Unknown · Dfactory Responsive Lightbox

Emad

·

Published

2024-06-09

·

Updated

2024-11-26

·

CVE-2024-31252

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dFactory Responsive Lightbox versions through 2.4.6
Description A Missing Authorization vulnerability has been identified in dFactory Responsive Lightbox. This issue may expose websites to unauthorized access. The estimated number of potentially affected devices is not specified. There is no information available about real-world incidents where this issue was exploited.
Recommendations For versions through 2.4.6, update to a version later than 2.4.6 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-31252

Affected Products

Dfactory Responsive Lightbox