What the vulnerability does
01Description
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
Explanation of Vulnerability in Simple Terms
ARMember versions up to 4.0.10 contain a privilege management flaw that allows authenticated users with low-level access to gain unauthorized administrative capabilities. An attacker can read, modify, or delete sensitive data and disrupt site operations. The vulnerability requires a valid user account but no additional user interaction.
What an attacker can do
Read, modify, or delete sensitive data; disrupt site availability; escalate privileges to admin level.
Potential impact on your site
Any registered user can escalate to admin, compromising data confidentiality, integrity, and site availability.
Conditions required to exploit
Valid user account with low-level privileges; network access to the site.
Key dates
External resources
Related vulnerabilities