Description
Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom CSS: from n/a through <= 1.4.0.
Problem types
Product status
Any version
Credits
Nabil Irawan (Patchstack Alliance)
References
vdp.patchstack.com/...-0-broken-access-control-vulnerability