What the vulnerability does
01Description
Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9.
Explanation of Vulnerability in Simple Terms
Rolo Slider versions up to 1.0.9 lack proper authorization checks, allowing authenticated users with low privileges to modify content they should not have access to. The vulnerability affects the integrity of site data across multiple components due to its changed scope. No confidentiality or availability impact is present. Sites running affected versions should update immediately.
What an attacker can do
Modify or alter site content and settings beyond their assigned permission level.
Potential impact on your site
Unauthorized users can alter slider content, potentially defacing or corrupting your site's presentation layer.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities