What the vulnerability does
01Description
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
Explanation of Vulnerability in Simple Terms
Finale Lite through version 2.18.0 fails to properly check user permissions before allowing access to sensitive functions. A logged-in user with low privileges can read, modify, or delete data they should not have access to, or perform administrative actions without authorization. This affects all data and functionality within the plugin.
What an attacker can do
Read, modify, or delete data; perform admin actions without proper authorization.
Potential impact on your site
Any registered user can access and modify sensitive plugin data or settings meant only for admins.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities