What the vulnerability does
01Description
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.
Explanation of Vulnerability in Simple Terms
Event Espresso 4 Decaf through version 4.10.44.decaf lacks proper authorization checks, allowing an attacker to modify certain data without authentication. The attack requires specific network conditions to succeed. This affects the integrity of event data but does not expose sensitive information or cause service disruption.
What an attacker can do
Modify event data without logging in, under specific network conditions.
Potential impact on your site
Unauthorized changes to event information; requires patching to prevent data tampering.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities