What the vulnerability does
01Description
Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.
Explanation of Vulnerability in Simple Terms
Sirv versions up to 7.2.0 lack proper authorization checks, allowing authenticated users to read and modify data they should not have access to. An attacker with a low-privilege account can view or alter other users' content without restriction. The vulnerability affects confidentiality and integrity but not availability. Update to version 8.2.4 or later to remediate.
What an attacker can do
Read and modify other users' data without authorization.
Potential impact on your site
User data and content may be exposed to or altered by other authenticated users on your Sirv instance.
Conditions required to exploit
Attacker must have a valid low-privilege Sirv account.
Key dates
External resources
Related vulnerabilities