PT-2025-17896 · Alphaefficiencyteam · Custom Login/Registration

Nguyen Ngoc Quang Bach

·

Published

2025-04-25

·

Updated

2025-04-25

·

CVE-2025-46535

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions AlphaEfficiencyTeam Custom Login and Registration versions 1.0.0 and earlier
Description The issue is related to a Missing Authorization vulnerability that allows exploiting incorrectly configured access control security levels. This affects the Custom Login and Registration functionality.
Recommendations For versions 1.0.0 and earlier, consider restricting access to the Custom Login and Registration module to minimize the risk of exploitation. As a temporary workaround, review and correct the configuration of access control security levels to ensure proper authorization is enforced.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-46535

Affected Products

Custom Login/Registration