What the vulnerability does
01Description
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
Explanation of Vulnerability in Simple Terms
Spectra versions up to 2.6.6 lack proper authorization checks, allowing authenticated users with low privileges to modify or disable site functionality. An attacker with a basic user account can alter settings they should not have access to, potentially disrupting site operations or changing configurations without admin approval.
What an attacker can do
Modify or disable site settings and functionality without proper authorization.
Potential impact on your site
Unauthorized users can change site configuration, disrupt functionality, or alter settings reserved for administrators.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities