What the vulnerability does
01Description
Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
Explanation of Vulnerability in Simple Terms
JupiterX Core versions 3.0.0 through 3.3.0 lack proper authorization checks on certain functions. A logged-in user with low privileges can modify site data or disrupt service without having permission to do so. Update to a version newer than 3.3.0 to resolve this issue.
What an attacker can do
A low-privilege logged-in user can modify site data or cause service disruption without authorization.
Potential impact on your site
Unauthorized users can alter content or cause downtime; data integrity and availability are at risk.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities