What the vulnerability does
01Description
Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4.
Explanation of Vulnerability in Simple Terms
Quick Event Manager through version 9.7.4 fails to properly check user permissions before allowing access to sensitive event data. An unauthenticated attacker can read event information without logging in. The vulnerability affects the product's core authorization logic and exposes confidential event details to anyone with network access.
What an attacker can do
Read event information without authentication.
Potential impact on your site
Sensitive event data becomes visible to unauthenticated visitors, potentially exposing private event details.
Conditions required to exploit
Network access to the affected Quick Event Manager instance; no login required.
Key dates
External resources
Related vulnerabilities