What the vulnerability does
01Description
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
Explanation of Vulnerability in Simple Terms
BEAR versions up to 1.1.4 lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a valid account can make requests that degrade site availability. No code execution or data theft is possible through this vulnerability.
What an attacker can do
Degrade site availability by triggering resource exhaustion or service disruption.
Potential impact on your site
Authenticated users can cause temporary unavailability or performance degradation of the BEAR component.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site.
Key dates
External resources
Related vulnerabilities