First published: Wed Oct 23 2024(Updated: )
Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
dFactory Responsive Lightbox | <2.4.8 |
Update to 2.4.8 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43924 has a high severity level due to the missing authorization which allows unauthorized access to certain functionalities.
To fix CVE-2024-43924, upgrade the dFactory Responsive Lightbox plugin to version 2.4.8 or later.
CVE-2024-43924 could allow attackers to access restricted functionalities, potentially compromising site security.
CVE-2024-43924 affects dFactory Responsive Lightbox versions prior to 2.4.8, specifically up to 2.4.7.
As a temporary workaround for CVE-2024-43924, consider disabling the plugin until you can upgrade to a secure version.