What the vulnerability does
01Description
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.
Explanation of Vulnerability in Simple Terms
FormCraft versions up to 1.2.7 lack proper authorization checks, allowing unauthenticated attackers to modify data through the application. The vulnerability requires no user interaction and can be exploited over the network. No confidentiality impact occurs, but data integrity is at risk.
What an attacker can do
Modify application data without authentication or permission.
Potential impact on your site
Unauthorized users can alter form submissions, settings, or other stored data without logging in.
Conditions required to exploit
Network access to the FormCraft application; no authentication required.
Key dates
External resources
Related vulnerabilities