What the vulnerability does
01Description
Missing Authorization vulnerability in bnayawpguy Resoto allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Resoto: from n/a through 1.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in bnayawpguy Resoto allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Resoto: from n/a through 1.0.8.
Explanation of Vulnerability in Simple Terms
Resoto versions up to 1.0.8 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with low-level credentials can change information within the application without proper permission validation. The vulnerability affects data integrity but does not expose sensitive information or disrupt availability.
What an attacker can do
Modify data in Resoto without proper authorization.
Potential impact on your site
Authenticated users can alter data they should not be able to change, risking data corruption and compliance violations.
Conditions required to exploit
Attacker must have a valid low-privilege account on the Resoto instance.
Key dates
External resources
Related vulnerabilities