What the vulnerability does
01Description
Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
What the vulnerability does
Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.
Explanation of Vulnerability in Simple Terms
Betheme versions up to 27.1.1 lack proper authorization checks, allowing authenticated users with low privileges to perform actions they should not be permitted to do. An attacker can read sensitive data, modify site content, or disrupt service availability. The vulnerability requires a valid user account but no special interaction from victims.
What an attacker can do
Read sensitive data, modify site content, or cause service disruption with a low-privilege user account.
Potential impact on your site
Authenticated users can bypass permission checks to access, modify, or disrupt your site beyond their assigned role.
Conditions required to exploit
Attacker must have a valid user account with low privileges; no victim interaction required.
Key dates
External resources
Related vulnerabilities