What the vulnerability does
01Description
Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.
Explanation of Vulnerability in Simple Terms
Sirv versions up to 7.1.2 lack proper authorization checks, allowing authenticated users to modify or disable features they should not have access to. An attacker with low-level account privileges can alter system settings or disable functionality without proper permission validation. The vulnerability affects integrity and availability but not confidentiality. Update to version 8.2.4 or later to resolve this issue.
What an attacker can do
Modify or disable system features and settings beyond their assigned permission level.
Potential impact on your site
Unauthorized users can alter your Sirv configuration, disable features, or degrade service availability.
Conditions required to exploit
Attacker must have a valid low-privilege account on the Sirv platform.
Key dates
External resources
Related vulnerabilities