What the vulnerability does
01Description
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
Explanation of Vulnerability in Simple Terms
MoveTo versions 6.2 and earlier lack authorization checks on critical functions. An unauthenticated attacker can read, modify, or delete data and disrupt service without any credentials or user interaction. The vulnerability affects all confidentiality, integrity, and availability of the application.
What an attacker can do
Read, modify, or delete data and disrupt service without authentication.
Potential impact on your site
Complete compromise of MoveTo data and availability; attackers can access, alter, or destroy content without credentials.
Conditions required to exploit
Network access to the MoveTo application; no authentication required.
Key dates
External resources
Related vulnerabilities