What the vulnerability does
01Description
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Explanation of Vulnerability in Simple Terms
Ninja Forms versions up to 3.6.25 lack proper authorization checks, allowing authenticated users with low privileges to access and modify form data and settings they should not be able to reach. An attacker with a basic user account can read sensitive form submissions and alter form configurations. Update to a version newer than 3.6.25 to resolve this issue.
What an attacker can do
Read other users' form submissions and modify form settings without proper authorization.
Potential impact on your site
Form data and configurations are exposed to unauthorized users; sensitive submissions may be compromised.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no special user interaction required.
Key dates
External resources
Related vulnerabilities