What the vulnerability does
01Description
Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.
Explanation of Vulnerability in Simple Terms
Slider Pro through version 4.8.6 fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify content they should not have access to. The vulnerability does not affect data confidentiality or system availability, only the integrity of protected content.
What an attacker can do
Modify content or settings that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can alter slider content, potentially defacing or corrupting your site's presentation layer.
Conditions required to exploit
Attacker must have a low-privilege account on the site and network access to the application.
Key dates
External resources
Related vulnerabilities