First published: Sun Jun 09 2024(Updated: )
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
dFactory Responsive Lightbox | <2.4.7 |
Update to 2.4.7 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31252 is classified as a Missing Authorization vulnerability affecting versions of dFactory Responsive Lightbox up to 2.4.6.
To mitigate CVE-2024-31252, update dFactory Responsive Lightbox to version 2.4.7 or later.
CVE-2024-31252 may allow unauthorized users to access restricted resources due to broken access control.
CVE-2024-31252 affects all versions of Responsive Lightbox from n/a up to 2.4.6.
Users of dFactory Responsive Lightbox versions up to 2.4.6 are at risk from CVE-2024-31252.