What the vulnerability does
01Description
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
Explanation of Vulnerability in Simple Terms
Educenter through version 1.5.5 fails to properly check user permissions before allowing modifications to certain data. A logged-in user with low privileges can alter information they should not have access to. The vulnerability requires authentication but no special user role, making it a moderate risk for multi-user sites.
What an attacker can do
Modify data or settings they lack permission to change.
Potential impact on your site
Unauthorized users can alter site content or configuration within their privilege scope.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities