What the vulnerability does
01Description
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
Explanation of Vulnerability in Simple Terms
Bricksforge versions up to 2.0.17 lack proper authorization checks, allowing unauthenticated attackers to perform administrative actions remotely. An attacker can read, modify, or delete site data without logging in. This affects all installations running the vulnerable version. Update immediately to a version newer than 2.0.17.
What an attacker can do
Read, modify, or delete site data without authentication.
Potential impact on your site
Attackers can compromise your entire site without a password, including data theft, defacement, or deletion.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities