What the vulnerability does
01Description
Missing Authorization vulnerability in HashThemes Square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in HashThemes Square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
HashThemes Square contains a missing authorization check that allows authenticated users with low privileges to modify data they should not have access to. An attacker with a low-privilege account can send network requests to alter information without additional user interaction. The vulnerability affects Square version 2.0.0 and earlier. Update to a version newer than 2.0.0 to remediate.
What an attacker can do
Modify data or settings they should not have permission to change.
Potential impact on your site
Low-privilege users can alter site data or configuration outside their intended role.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities