First published: Thu Jan 16 2025(Updated: )
Missing Authorization vulnerability in Thorn Technologies LLC Cache Sniper for Nginx allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through 1.0.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thorn Technologies Cache Sniper for Nginx | >n/a<=1.0.4.2 | |
WordPress Cache Sniper for Nginx | <=1.0.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23776 is considered a high severity vulnerability due to its impact on access control.
To fix CVE-2025-23776, update Cache Sniper for Nginx to version 1.0.4.3 or later, ensuring proper access control configurations.
CVE-2025-23776 is caused by missing authorization checks in Cache Sniper for Nginx, allowing unauthorized access through misconfigured access controls.
Versions of Cache Sniper for Nginx from n/a through 1.0.4.2 are affected by CVE-2025-23776.
Yes, CVE-2025-23776 is exploitable due to the missing authorization controls that can be leveraged by attackers.