PT-2025-4919 · Sanjaysolutions · Sanjaysolutions Loginplus

Mika

·

Published

2025-01-16

·

Updated

2025-01-17

·

CVE-2025-23514

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Sanjaysolutions Loginplus versions n/a through 1.2
Description The issue is related to a missing authorization vulnerability in Sanjaysolutions Loginplus, which allows accessing functionality not properly constrained by Access Control Lists (ACLs). This means that certain features or areas of the system are not correctly restricted, potentially allowing unauthorized access.
Recommendations For Sanjaysolutions Loginplus versions n/a through 1.2, consider restricting access to sensitive functionality until a proper fix is applied, ensuring that all access is properly constrained by ACLs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-23514

Affected Products

Sanjaysolutions Loginplus