What the vulnerability does
01Description
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.
Explanation of Vulnerability in Simple Terms
JetFormBuilder versions up to 3.0.8 contain a privilege management flaw that allows high-privileged users to read sensitive data, modify site content, or disrupt service. The vulnerability requires administrator-level access to exploit. Sites running affected versions should update to the latest release immediately.
What an attacker can do
Read sensitive data, modify site content, or disrupt service if they have admin-level access.
Potential impact on your site
A compromised admin account could be used to steal data, alter forms, or take the site offline.
Conditions required to exploit
Attacker must have administrator or equivalent high-privilege account on the site.
Key dates
External resources
Related vulnerabilities