What the vulnerability does
01Description
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
Explanation of Vulnerability in Simple Terms
Spiffy Calendar versions up to 4.9.10 lack proper authorization checks on certain operations. A logged-in user with low privileges can modify or delete calendar data without proper permission validation. The vulnerability does not expose sensitive information but allows unauthorized changes to calendar integrity.
What an attacker can do
Modify or delete calendar data without proper authorization.
Potential impact on your site
Unauthorized users can alter or remove calendar entries, disrupting scheduling and event management.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities