What the vulnerability does
01Description
Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.5.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.5.0.
Explanation of Vulnerability in Simple Terms
Site Reviews through version 6.5.0 fails to properly check user permissions before allowing modifications to review data. A logged-in user with low privileges can alter reviews they should not have access to. The vulnerability does not expose sensitive information or crash the site, but allows unauthorized changes to review content.
What an attacker can do
Modify reviews without proper authorization.
Potential impact on your site
Logged-in users can alter reviews they don't own, compromising review integrity.
Conditions required to exploit
Attacker must be logged in with low-level user account.
Key dates
External resources
Related vulnerabilities