What the vulnerability does
01Description
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
Explanation of Vulnerability in Simple Terms
PropertyHive versions up to 2.0.6 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter records without proper permission validation. The vulnerability affects integrity but not confidentiality or availability. Update to a version newer than 2.0.6 to resolve this issue.
What an attacker can do
Modify data or records that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can alter property listings, settings, or other data depending on PropertyHive's data model.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the PropertyHive installation.
Key dates
External resources
Related vulnerabilities