What the vulnerability does
01Description
Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.4.
Explanation of Vulnerability in Simple Terms
AtomChat versions 1.1.4 and earlier lack proper authorization checks, allowing unauthenticated attackers to read sensitive information over the network. The vulnerability requires no user interaction and can be exploited remotely. An attacker can access data they should not be permitted to view without needing valid credentials.
What an attacker can do
Read sensitive information without authentication.
Potential impact on your site
Confidential data may be exposed to unauthenticated users if AtomChat is deployed on your site.
Conditions required to exploit
Network access to the AtomChat instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities