What the vulnerability does
01Description
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
Explanation of Vulnerability in Simple Terms
WatchTowerHQ versions up to 3.6.16 contain a privilege management flaw that allows unauthenticated attackers to gain full control of the application over the network. The vulnerability requires no user interaction and affects confidentiality, integrity, and availability. Update to version 4.0.7 or later to remediate.
What an attacker can do
Read, modify, or delete any data; run their own code on the server; disrupt service.
Potential impact on your site
Complete compromise of WatchTowerHQ and any data it manages; attackers can impersonate administrators.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities