Missing Authorization Vulnerability in DirectoryPress by Designinvento
CVE-2026-23548
5.3MEDIUM
What is CVE-2026-23548?
A missing authorization vulnerability exists in DirectoryPress by Designinvento, allowing attackers to exploit incorrectly configured access control security levels. This issue affects versions up to 3.6.25, potentially exposing sensitive data and functionalities to unauthorized users. Proper security measures and updates are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
DirectoryPress 0 <= 3.6.25