What the vulnerability does
01Description
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
Explanation of Vulnerability in Simple Terms
The Salon Booking System versions 8.6 and earlier contain a privilege management flaw that allows high-privileged users to perform unauthorized actions when a victim interacts with a malicious link or page. An attacker with administrative or elevated access can read, modify, or delete sensitive data, or disrupt service availability. The vulnerability requires both high privileges and user interaction to exploit.
What an attacker can do
Read, modify, or delete sensitive data; disrupt service availability.
Potential impact on your site
A compromised admin account or trusted user could be tricked into actions that expose or corrupt booking data, customer information, or system availability.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent); victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities