What the vulnerability does
01Description
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
Explanation of Vulnerability in Simple Terms
CP Multi View Event Calendar versions up to 1.4.10 lack proper authorization checks, allowing authenticated users to modify event data they should not have access to. An attacker with a low-privilege account can alter calendar events without proper permission validation. The vulnerability affects the integrity of event information but does not expose sensitive data or disrupt availability.
What an attacker can do
Modify calendar events belonging to other users or restricted event data.
Potential impact on your site
Event data can be altered by unauthorized users, compromising calendar accuracy and trust.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities