What the vulnerability does
01Description
Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.
Explanation of Vulnerability in Simple Terms
WCP Contact Form versions up to 3.1.0 lack proper authorization checks, allowing authenticated users to modify form data they should not have access to. An attacker with a low-privilege account can alter contact form submissions or settings. The vulnerability requires login credentials but does not require user interaction beyond normal site access.
What an attacker can do
Modify contact form data or settings belonging to other users or forms.
Potential impact on your site
Contact form submissions and configurations may be altered by unauthorized users with site access.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities