What the vulnerability does
01Description
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.
Explanation of Vulnerability in Simple Terms
Betheme versions up to 27.1.1 lack proper authorization checks, allowing high-privilege users to access or modify functionality they should not have permission to use. The vulnerability affects confidentiality, integrity, and availability of the site. Scope is changed, meaning the impact may extend beyond the vulnerable component itself.
What an attacker can do
A high-privilege user can access or modify restricted functionality beyond their intended permissions.
Potential impact on your site
Privileged users may exceed their intended access scope, risking data exposure, unauthorized changes, or service disruption.
Conditions required to exploit
Attacker must have high-level privileges (e.g., admin or editor role) on the site.
Key dates
External resources
Related vulnerabilities