What the vulnerability does
01Description
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
Explanation of Vulnerability in Simple Terms
JupiterX Core through version 3.3.8 contains an authorization flaw that allows unauthenticated attackers to read, modify, or delete data on the site without logging in. The vulnerability stems from incorrect permission checks in the application logic. No user interaction is required; an attacker can exploit this remotely over the network.
What an attacker can do
Read, modify, or delete site data without authentication.
Potential impact on your site
Attackers can access, alter, or destroy your site's content and data without a password.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities