What the vulnerability does
01Description
Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2.
Explanation of Vulnerability in Simple Terms
MoveTo versions 6.2 and earlier lack proper authorization checks, allowing unauthenticated attackers to disrupt service availability. The vulnerability affects the entire application scope due to its network-accessible nature. No authentication or user interaction is required to trigger the attack. Organizations running affected versions should update immediately.
What an attacker can do
Disrupt service availability without authentication or user interaction.
Potential impact on your site
Service outages or degraded performance affecting all users of the MoveTo application.
Conditions required to exploit
Network access to the MoveTo application; no authentication required.
Key dates
External resources
Related vulnerabilities