What the vulnerability does
01Description
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
Explanation of Vulnerability in Simple Terms
ARMember versions up to 4.0.10 contain a privilege management flaw that allows authenticated users with low privileges to modify data and disrupt service. An attacker with a basic user account can escalate their capabilities to alter site content and cause availability issues. The vulnerability requires network access and valid login credentials but no additional user interaction.
What an attacker can do
Modify site data and cause service disruption with a low-privilege user account.
Potential impact on your site
Authenticated users can alter content and cause downtime; data integrity and availability at risk.
Conditions required to exploit
Valid login credentials for a low-privilege user account; network access to the site.
Key dates
External resources
Related vulnerabilities