What the vulnerability does
01Description
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
Explanation of Vulnerability in Simple Terms
JetEngine versions up to 3.2.4 contain a privilege management flaw that allows authenticated users with low-level access to perform actions reserved for higher-privilege roles. An attacker with a basic user account can read, modify, or delete sensitive data and potentially disrupt site functionality. Update to a version newer than 3.2.4 immediately.
What an attacker can do
Read, modify, or delete data and disrupt site operations using a low-privilege user account.
Potential impact on your site
Unauthorized users can access and alter protected content, compromise data integrity, and cause service disruption.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities