What the vulnerability does
01Description
Missing Authorization vulnerability in Pechenki TelSender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TelSender: from n/a through 1.14.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Pechenki TelSender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TelSender: from n/a through 1.14.11.
Explanation of Vulnerability in Simple Terms
TelSender versions up to 1.14.11 lack proper authorization checks, allowing authenticated users with low privileges to modify or disable functionality they should not access. An attacker with a basic user account can alter system settings or disable features without proper permission validation. The vulnerability affects integrity and availability but not confidentiality.
What an attacker can do
Modify or disable TelSender features and settings without proper authorization.
Potential impact on your site
Unauthorized users can alter TelSender configuration, potentially disrupting messaging functionality or changing system behavior.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the system.
Key dates
External resources
Related vulnerabilities