What the vulnerability does
01Description
Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.
Explanation of Vulnerability in Simple Terms
Simple Staff List through version 2.2.4 does not properly check user permissions before allowing access to staff data. A logged-in user with low privileges can view staff information they should not have access to. The vulnerability requires an active user account but no special interaction from the victim.
What an attacker can do
View staff member information that should be restricted to higher-privilege users.
Potential impact on your site
Staff data may be exposed to users who should not see it, potentially revealing contact info or internal details.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities