What the vulnerability does
01Description
Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.
Explanation of Vulnerability in Simple Terms
WCP Contact Form through version 3.1.0 fails to properly restrict access to sensitive data. An attacker can read information without authentication by sending a direct request to the application. No user interaction or special privileges are required. Update to a version newer than 3.1.0.
What an attacker can do
Read sensitive data from the contact form without logging in.
Potential impact on your site
Visitor and contact form submission data may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; no authentication required.
Key dates
External resources
Related vulnerabilities