What the vulnerability does
01Description
Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.
Explanation of Vulnerability in Simple Terms
BBS e-Popup versions up to 2.4.5 lack proper authorization checks, allowing unauthenticated attackers to modify data and disrupt service. The vulnerability requires only network access and no user interaction. An attacker can alter popup settings or disable functionality without authentication.
What an attacker can do
Modify popup settings and disrupt service without logging in.
Potential impact on your site
Attackers can alter or disable popups, affecting user experience and potentially site functionality.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities